Sale of a 0-day exploit for authenticated SQL Injection in the OpenCart core
Dark Web2026-07-01, 12:40
Sale of a 0-day exploit for authenticated SQL Injection in the OpenCart core
For informational purposes only
Vulnerable versions: starting from OC 2.0 to the current version
Type of vulnerability: authenticated SQL Injection
Price: auction (start — $500, step — $100, blitz — $2000)
The author announces the sale of an SQL injection in the official OpenCart controller, which, according to the seller, is located in the product core starting from version OC 2.0 and up to the latest current version. The author specifically emphasizes that the vulnerability does not have a patch.
According to the seller's description, the main application scenario is privilege escalation through extracting an administrator's password hash, password change code, or any other data available in the database from the database.
The author explicitly states that the vulnerability is suitable for cases where the attacker has access to the admin panel, but does not have the rights to create a backup copy.
OpenCart is a popular open-source CMS for online stores, especially in the small and medium e-commerce segment. According to BuiltWith, there are about 190 thousand active sites on OpenCart worldwide and more than 922 thousand sites that have used the platform historically.
Vendors
Products