VU#614868: OpenCart ecommerce platform contains directory traversal vulnerability
Cybersecurity Classified by Officially
Overview The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability. The extension installation process extracts uploaded .zip files then uses the zip entry filenames as filesystem paths, without validating that the resolved path stays inside the intended directory. This vulnerability is tracked as CVE-2026-18412. …
This is an extract. The publication continues at the source.
Read the original at the source: https://kb.cert.org/vuls/id/614868
Officially imported this from CERT Coordination Center’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- CERT Coordination Center — imported from official source
- Official source
- https://www.kb.cert.org/vuls/atomfeed/ ATOM
- Imported
- September 15, 2026 20:57
- Versions
- 1 recorded
- Identity
-
https://kb.cert.org/vuls/id/614868