Executive brief
OpenCart is an open-source e-commerce platform used to build and manage online stores. The extension installer fails to validate file paths when extracting uploaded extensions, allowing an attacker with admin credentials to upload a malicious extension containing traversal sequences (../) and write files such as PHP web shells to the server's web directory. This enables remote code execution with the privileges of the OpenCart application.
Technical details
The vulnerability is a path traversal flaw (CWE-22) in OpenCart v4.2.0.0's extension installer. When users upload extensions as .ocmod.zip files, the installer extracts the archive but does not validate that extracted file paths remain within the intended extraction directory. An attacker can craft a malicious .ocmod.zip extension containing path traversal sequences (e.g., ../../shell.php) to write arbitrary files into the webroot. The attack requires valid administrator credentials to access the extension installation interface. Successful exploitation enables arbitrary file upload and remote code execution (RCE) with the same privileges as the OpenCart process. At the time of disclosure, no patch was available and the vendor could not be reached for coordination.
Affected products
- OpenCart OpenCart 4.2.0.0 and possibly other 4.x versions
Timeline
- 2026-08-10: disclosed
- 2026-08-10: advisory: CERT/CC VU#614868 published