-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability manifests in the marketplace installer's ZIP processing. Multiple references point to line 383 in installer.php where extraction occurs. Zip Slip vulnerabilities typically occur when using ZipArchive::extractTo() or similar methods without validating entry names. The PoC demonstrates exploitation through this endpoint, and OpenCart's lack of path normalization/sanitization before extraction enables traversal. The high confidence comes from direct advisory references to this file/location and the attack pattern matching classic Zip Slip scenarios.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| opencart/opencart | composer | >= 4.0.0.0 |
Ongoing coverage of React2Shell