Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-01-26T06:47:35

Updated: 2024-08-03T16:53:17.248Z

Reserved: 2021-01-25T00:00:00

Link: CVE-2021-3291

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-01-26T18:16:29.677

Modified: 2021-03-09T21:34:32.547

Link: CVE-2021-3291

cve-icon Redhat

No data.