OpenCart through 3.0.2.0 allows directory traversal in the editDownload
function in admin\model\catalog\download.php
via admin/index.php?route=catalog/download/edit
, related to the download_id
. For example, an attacker can download ../../config.php
.
{ "nvd_published_at": "2018-05-26T20:29:00Z", "cwe_ids": [ "CWE-22" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-04-23T17:28:15Z" }