CVE-2014-3990

CRITICAL

OpenCart < 1.5.6.4 - Server-Side Request Forgery and XML External Entity Injection via Cart Update

Title source: llm
STIX 2.1

Description

The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly conduct XML External Entity (XXE) attacks and execute arbitrary code via a crafted serialized PHP object, related to the quantity parameter in an update request.

References (6)

Core 6
Core References
Exploit, Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/532763/100/0/threaded
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://github.com/opencart-ce/opencart-ce/commit/c2aafc823bd85876f5e888f8ebc421069a5e076f
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Jul/67
Exploit, Third Party Advisory x_refsource_misc
http://karmainsecurity.com/KIS-2014-08
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/127460/OpenCart-1.5.6.4-PHP-Object-Injection.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68529

Scores

CVSS v3 9.8
EPSS 0.0687
EPSS Percentile 93.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-611 CWE-918
Status published
Products (1)
opencart/opencart < 1.5.6.4
Published Mar 20, 2018
Tracked Since Feb 18, 2026