Vulnerabilities > CVE-2014-3990 - Server-Side Request Forgery (SSRF) vulnerability in Opencart

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
opencart
CWE-918
critical

Summary

The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly conduct XML External Entity (XXE) attacks and execute arbitrary code via a crafted serialized PHP object, related to the quantity parameter in an update request.

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/127460/KIS-2014-08.txt
idPACKETSTORM:127460
last seen2016-12-05
published2014-07-14
reporterEgiX
sourcehttps://packetstormsecurity.com/files/127460/OpenCart-1.5.6.4-PHP-Object-Injection.html
titleOpenCart 1.5.6.4 PHP Object Injection