PT-2026-27786 · Opencart · Opencart Core
Saud Alenazi
·
Published
2026-03-25
·
Updated
2026-03-30
·
CVE-2024-58341
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenCart Core version 4.0.2.3
Description
The software contains a SQL injection flaw that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL code through the
search parameter. This is achieved by sending GET requests to the product search endpoint with malicious search values, enabling the extraction of sensitive database information using boolean-based blind or time-based blind SQL injection techniques. The API endpoint involved is the product search endpoint.Recommendations
Apply a fix for OpenCart Core version 4.0.2.3.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opencart Core