PT-2021-19973 · Zen Cart · Zen Cart

Published

2021-01-26

·

Updated

2022-05-24

·

CVE-2021-3291

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zen Cart version 1.5.7b
Description The issue allows admins to execute arbitrary OS commands by inspecting an HTML radio input element within the modules edit page and inserting a command.
Recommendations For Zen Cart version 1.5.7b, as a temporary workaround, consider restricting access to the modules edit page to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3291
GHSA-38F9-4VHQ-9CR8

Affected Products

Zen Cart