CVE-2014-3990
CRITICALOpenCart < 1.5.6.4 - Server-Side Request Forgery and XML External Entity Injection via Cart Update
Title source: llmDescription
The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly conduct XML External Entity (XXE) attacks and execute arbitrary code via a crafted serialized PHP object, related to the quantity parameter in an update request.
References (6)
Core 6
Core References
Exploit, Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/532763/100/0/threaded
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://github.com/opencart-ce/opencart-ce/commit/c2aafc823bd85876f5e888f8ebc421069a5e076f
Exploit, Mailing List, Third Party Advisory mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Jul/67
Exploit, Third Party Advisory x_refsource_misc
http://karmainsecurity.com/KIS-2014-08
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/127460/OpenCart-1.5.6.4-PHP-Object-Injection.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/68529
Scores
CVSS v3
9.8
EPSS
0.0687
EPSS Percentile
93.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-611
CWE-918
Status
published
Products (1)
opencart/opencart
< 1.5.6.4
Published
Mar 20, 2018
Tracked Since
Feb 18, 2026