PT-2024-12108 · Cs Cart Multivendor+1 · Pdf Add-On+1

Published

2024-09-24

·

Updated

2024-09-30

·

CVE-2023-26687

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CS-Cart MultiVendor version 4.16.1
Description The issue allows remote attackers to obtain sensitive information via the product data parameter in the PDF Add-on. This is a Directory Traversal vulnerability, which can be exploited to access files or directories that are not intended to be accessible.
Recommendations For CS-Cart MultiVendor version 4.16.1, consider disabling the PDF Add-on or restricting access to the product data parameter until a patch is available. As a temporary workaround, avoid using the product data parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-26687

Affected Products

Cs-Cart Multivendor
Pdf Add-On