Vulnerability Description
OpenCart through 3.0.2.0 allows directory traversal in the editDownload function in admin\model\catalog\download.php via admin/index.php?route=catalog/download/edit, related to the download_id. For example, an attacker can download ../../config.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opencart | Opencart | <= 3.0.2.0 |
Related Weaknesses (CWE)
References
- http://www.bigdiao.cc/2018/05/24/Opencart-v3-0-2-0/ExploitThird Party Advisory
- http://www.bigdiao.cc/2018/05/24/Opencart-v3-0-2-0/ExploitThird Party Advisory
FAQ
What is CVE-2018-11495?
CVE-2018-11495 is a vulnerability with a CVSS score of 4.9 (MEDIUM). OpenCart through 3.0.2.0 allows directory traversal in the editDownload function in admin\model\catalog\download.php via admin/index.php?route=catalog/download/edit, related to the download_id. For ex...
How severe is CVE-2018-11495?
CVE-2018-11495 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-11495?
Check the references section above for vendor advisories and patch information. Affected products include: Opencart Opencart.