VU#614868: OpenCart ecommerce platform contains directory traversal vulnerability

CERT Coordination Center Version 1 original current

Imported from official source

Overview The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability. The extension installation process extracts uploaded .zip files then uses the zip entry filenames as filesystem paths, without validating that the resolved path stays inside the intended directory. This vulnerability is tracked as CVE-2026-18412. …

This version

Version
1 of 1
Recorded
September 15, 2026 20:57
Change
Initial
Content hash
1035be16fca875ee33d6ebb0b42bca19
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.