Description
OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.
References (5)
Core 5
Core References
Exploit, Third Party Advisory
https://github.com/A3h1nt/CVEs/blob/main/OpenCart/Readme.md
Exploit, Third Party Advisory
https://github.com/PawaritSanguanpang/CVEs/blob/main/OpenCart/CVE-2024-36694/README.md
Issue Tracking, Vendor Advisory
https://github.com/opencart/opencart/issues/13863
Exploit, Third Party Advisory
https://medium.com/@pawarit.sanguanpang/opencart-v4-0-2-3-server-side-template-injection-0b173a3bdcf9
Scores
CVSS v3
7.2
EPSS
0.0098
EPSS Percentile
76.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (2)
opencart/opencart
4.0.2.3
opencart/opencart
0Packagist
Published
Dec 18, 2024
Tracked Since
Feb 18, 2026