GHSA-c9r9-3h38-r7vj

Suggest an improvement
Source
https://github.com/advisories/GHSA-c9r9-3h38-r7vj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-c9r9-3h38-r7vj/GHSA-c9r9-3h38-r7vj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-c9r9-3h38-r7vj
Aliases
Published
2022-05-17T02:20:07Z
Modified
2026-09-10T03:49:32Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Authenticated RCE in Zen Cart 1.5.5e
Details

The traverseStrictSanitize function in admin_dir/includes/classes/AdminRequestSanitizer.php in ZenCart 1.5.5e mishandles key strings, which allows remote authenticated users to execute arbitrary PHP code by placing that code into an invalid array index of the admin_name array parameter to admin_dir/login.php, if there is an export of an error-log entry for that invalid array index.

Database specific
{
    "cwe_ids":  [
        "CWE-94"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-07-07T00:08:36Z",
    "nvd_published_at":  "2017-07-27T06:29:00Z",
    "severity":  "HIGH"
}
References

Affected packages

Packagist / zencart/zencart

Package

Name
zencart/zencart
Purl
pkg:composer/zencart/zencart

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

v1.*
v1.5.6a
v1.5.6b
v1.5.6b-2019-05-27
v1.5.6
v1.5.7a
v1.5.7b
v1.5.7
v1.5.8a
v1.5.8-alpha2
v1.5.8
v2.*
v2.0.0-alpha1
v2.0.0-beta1
v2.0.0-rc1
v2.0.0-rc2
v2.0.0
v2.0.1
v2.1.0-alpha1
v2.1.0-alpha2
v2.1.0-beta1
v2.1.0
v2.2.0-alpha
v2.2.1
v2.2.2

Database specific

last_known_affected_version_range
"< 1.5.5e"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-c9r9-3h38-r7vj/GHSA-c9r9-3h38-r7vj.json"