CVE-2014-3990

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
20/03/2018
Last modified:
25/04/2019

Description

The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly conduct XML External Entity (XXE) attacks and execute arbitrary code via a crafted serialized PHP object, related to the quantity parameter in an update request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opencart:opencart:*:*:*:*:*:*:*:* 1.5.6.4 (including)