CVE-2024-36694

HIGH8.0EPSS 0.98%

openCart Server-Side Template Injection (SSTI) vulnerability

Published: 7/17/2024Modified: 4/23/2025

Description

OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
osvCVSS 3.1HIGH8.0CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

References (7)