PT-2022-16469 · Skyoftech · Skyoftech So Listing Tabs

Alexey Smirnov

+4

·

Published

2022-05-17

·

Updated

2022-05-27

·

CVE-2022-24108

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Skyoftech So Listing Tabs module version 2.2.0 for OpenCart
Description The issue allows a remote attacker to inject a serialized PHP object via the setting parameter, potentially resulting in the ability to write to files on the server, cause Denial of Service (DoS), and achieve remote code execution because of deserialization of untrusted data.
Recommendations For Skyoftech So Listing Tabs module version 2.2.0, consider disabling the module until a patch is available to prevent exploitation. Restrict access to the setting parameter to minimize the risk of deserialization of untrusted data. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24108

Affected Products

Skyoftech So Listing Tabs