CVE-2024-58341
HIGHOpenCart Core 4.0.2.3 SQL Injection via search Parameter
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2024-58341. PoCs published by Saud Alenazi.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in OpenCart Core 4.0.2.3 via the 'search' parameter in the product search functionality. It includes payloads for boolean-based and time-based blind SQLi, confirming the vulnerability's exploitability.
Description
OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'search' parameter. Attackers can send GET requests to the product search endpoint with malicious 'search' values to extract sensitive database information using boolean-based blind or time-based blind SQL injection techniques.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in OpenCart Core 4.0.2.3 via the 'search' parameter in the product search functionality. It includes payloads for boolean-based and time-based blind SQLi, confirming the vulnerability's exploitability.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N