OpenCart是中国OpenCart团队的一套开源的电子商务系统。该系统提供产品评论、产品评分、产品添加等模块。 OpenCart 4.0.2.3版本存在安全漏洞,该漏洞源于对搜索参数的处理不当,可能导致未经验证攻击者通过向产品搜索端点发送带有恶意搜索值的GET请求,利用基于布尔或时间的盲注技术操纵数据库查询并提取敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Opencart | OpenCart Core | 4.0.2.3 |
affected |
4.1.0.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Opencart | OpenCart Core | 4.0.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet