PT-2026-55720 · Kirilkirkov · Ecommerce-Codeigniter-Bootstrap
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
kirilkirkov Ecommerce-CodeIgniter-Bootstrap versions up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7
Description
A remote attack can be initiated through the manipulation of the
shopping cart argument in the getCartItems() function within the application/libraries/ShoppingCart.php library. This manipulation leads to deserialization, a process where data is converted back into an object, which can be exploited to execute unauthorized code.Recommendations
Apply patch 49b20f53de2b7ec34e920b11c863f1491d911a04 to resolve the issue.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ecommerce-Codeigniter-Bootstrap