Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Zen Cart. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the findPluginAdminPage function. The issue results from the lack of proper validation of user-supplied data prior to passing it to a PHP include function. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the service account. Was ZDI-CAN-21408.
Metrics
Affected Vendors & Products
References
History
Fri, 23 Aug 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Zen-cart
Zen-cart zen Cart |
|
Weaknesses | CWE-829 | |
CPEs | cpe:2.3:a:zen-cart:zen_cart:1.5.8a:*:*:*:*:*:*:* | |
Vendors & Products |
Zen-cart
Zen-cart zen Cart |
|
Metrics |
cvssV3_1
|
Wed, 21 Aug 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Zen Cart
Zen Cart zen Cart |
|
CPEs | cpe:2.3:a:zen_cart:zen_cart:*:*:*:*:*:*:*:* | |
Vendors & Products |
Zen Cart
Zen Cart zen Cart |
|
Metrics |
ssvc
|
Wed, 21 Aug 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Zen Cart. Authentication is not required to exploit this vulnerability. The specific flaw exists within the findPluginAdminPage function. The issue results from the lack of proper validation of user-supplied data prior to passing it to a PHP include function. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the service account. Was ZDI-CAN-21408. | |
Title | Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability | |
Weaknesses | CWE-98 | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: zdi
Published: 2024-08-21T16:15:27.278Z
Updated: 2024-08-21T17:14:11.364Z
Reserved: 2024-06-07T19:10:09.754Z
Link: CVE-2024-5762
Vulnrichment
Updated: 2024-08-21T17:13:34.307Z
NVD
Status : Analyzed
Published: 2024-08-21T17:15:08.810
Modified: 2024-08-23T16:43:19.497
Link: CVE-2024-5762
Redhat
No data.