Impact
The vulnerability is an insecure deserialization flaw in MaxD Lightning Module versions 4.43 and 4.44 when used on the OpenCart platform. By manipulating the query parameter li_op/md, an attacker can trigger the module to deserialize untrusted data, potentially allowing arbitrary code to be executed on the server. The flaw is classified under CWE‑502 and CWE‑20. The provided description indicates that the attack requires a high level of complexity and is difficult to execute, yet the vulnerability has been publicly disclosed and may be exploited remotely.
Affected Systems
The affected systems are installations of MaxD Lightning Module on OpenCart e‑commerce sites that are running versions 4.43 or 4.44. No other vendors or products are explicitly listed. The vulnerability is tied to the specific processing of the li_op/md argument within the module.
Risk and Exploitability
The CVSS score of 2.3 indicates a low overall severity, and the EPSS score of less than 1% reflects a very low probability of exploitation in the wild. The flaw is not included in the CISA KEV catalog. Even though exploiting the issue is complex, the fact that it can be triggered remotely suggests that an attacker could use it to achieve remote code execution if successful. Organizations should treat this as a low‑priority threat but still remediate to eliminate the risk.
OpenCVE Enrichment
EUVD