The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier...
Vulnerability Description
The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly conduct XML External Entity (XXE) attacks and execute arbitrary code via a crafted serialized PHP object, related to the quantity parameter in an update request.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-3990
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/archive/1/532763/100/0/threaded
- https://github.com/opencart-ce/opencart-ce/commit/c2aafc823bd85876f5e888f8ebc421069a5e076f
- http://seclists.org/fulldisclosure/2014/Jul/67
- http://karmainsecurity.com/KIS-2014-08
- http://packetstormsecurity.com/files/127460/OpenCart-1.5.6.4-PHP-Object-Injection.html
- http://www.securityfocus.com/bid/68529
More from opencart
View All →Affected Vendor
opencart
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.