8.8
CVSSv3

CVE-2023-47444

Published: 15/11/2023 Updated: 21/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untrusted data inside config.php and admin/config.php, resulting in remote code execution on the underlying server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opencart opencart

Github Repositories

Data for my italian youtube channel

Youtube Material – Italian Questa repository contiene tutto il materiale didattico che ho creato per il mio canale youtube italiano in cui mi concentro sull'informatica da svariati punti di vista e con un particolare focus sulla programmazione e sulla sicurezza informatica Link di interesse: Youtube – Leonardo Tamiano Blog Donazione – Supporta il mio la

Data for my italian youtube channel

Youtube Material – Italian Questa repository contiene tutto il materiale didattico che ho creato per il mio canale youtube italiano in cui mi concentro sull'informatica da svariati punti di vista e con un particolare focus sulla programmazione e sulla sicurezza informatica Link di interesse: Youtube – Leonardo Tamiano Blog Donazione – Supporta il mio la

Recent Articles

OpenCart owner turns air blue after researcher discloses serious vuln
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Web storefront maker fixed the flaw, but not before blasting infoseccer

The owner of the e-commerce store management system OpenCart has responded with hostility to a security researcher disclosing a vulnerability in the product. Penetration tester Mattia Brollo brought a static code injection vulnerability to the attention of OpenCart by opening a GitHub issue on October 14, only to be met with numerous dismissive and offensive responses from Daniel Kerr, OpenCart's owner. Before Kerr's involvement, Brollo claims he spent close to a month trying to reach OpenCart v...