CVE-2024-58341

HIGH

OpenCart Core 4.0.2.3 SQL Injection via search Parameter

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-58341. PoCs published by Saud Alenazi.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in OpenCart Core 4.0.2.3 via the 'search' parameter in the product search functionality. It includes payloads for boolean-based and time-based blind SQLi, confirming the vulnerability's exploitability.

Description

OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'search' parameter. Attackers can send GET requests to the product search endpoint with malicious 'search' values to extract sensitive database information using boolean-based blind or time-based blind SQL injection techniques.

Exploits (1)

exploitdb WORKING POC
by Saud Alenazi · textwebappsphp
https://www.exploit-db.com/exploits/51940

This exploit demonstrates a SQL injection vulnerability in OpenCart Core 4.0.2.3 via the 'search' parameter in the product search functionality. It includes payloads for boolean-based and time-based blind SQLi, confirming the vulnerability's exploitability.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: OpenCart Core 4.0.2.3
No auth needed
Prerequisites: access to the target URL with the vulnerable endpoint
devstral-2 · analyzed Apr 09, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-51940
https://www.exploit-db.com/exploits/51940
Product product
Official Product Homepage
https://www.opencart.com/
Patch product patch
Product Reference
https://github.com/opencart/opencart/releases
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenCart Core 4.0.2.3 SQL Injection via search Parameter
https://www.vulncheck.com/advisories/opencart-core-sql-injection-via-search-parameter

Scores

CVSS v3 8.2
EPSS 0.0012
EPSS Percentile 31.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (3)
opencart/opencart 4.0.2.3
Opencart/OpenCart Core 4.0.2.3
Opencart/OpenCart Core 4.1.0.0
Published Mar 25, 2026
Tracked Since Mar 25, 2026