PT-2026-69852 · Opencart · Opencart
CVE-2026-18412
·
Published
2026-08-10
·
Updated
2026-08-12
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenCart version 4.2.0.0
Description
The extension installer fails to validate that extracted paths from uploaded
.ocmod.zip files remain within the intended directory. This allows an attacker to use directory traversal sequences, such as ../, to write arbitrary files, including PHP web shells, directly into the webroot directory.Recommendations
Update OpenCart version 4.2.0.0 to a newer version that contains a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opencart