{"document":{"acknowledgments":[{"urls":["https://kb.cert.org/vuls/id/614868#acknowledgements"]}],"category":"CERT/CC Vulnerability Note","csaf_version":"2.0","notes":[{"category":"summary","text":"### Overview\r\nThe OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability. The extension installation process extracts uploaded `.zip` files then uses the zip entry filenames as filesystem paths, without validating that the resolved path stays inside the intended directory. This vulnerability is tracked as CVE-2026-18412.\r\n\r\n### Description\r\nOpenCart is a free, open‑source e‑commerce solution designed to help businesses build and manage online stores. \r\n\r\nOpenCart extensions are uploaded as zip files with `.ocmod.zip` extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these zip files, but does not validate that the extracted paths stay inside the intended extraction directory. An attacker can craft a malicious extension containing file path traversal sequences, such as `../`. With this vulnerability, an attacker can write files, such as a PHP web shell, into the webroot directory.\r\n\r\n### Impact\r\nIf a user with valid admininistrator credentials installs a malicious extension, it could allow a user to remotely execute code with the same privileges that OpenCart has on the target server. This includes the potential creation of a web shell, which could further enable remote execution of system-level commands. The vulnerability was confirmed against version 4.2.0.0, but other 4.x versions of OpenCart may be affected.\r\n\r\n### Solution\r\nUnfortunately, OpenCart could not be reached to coordinate this vulnerability, and a patch is not available at the time of this writing. The CERT/CC recommends that OpenCart users update to the latest version and avoid installing extensions from unknown or untrusted sources. Additionally, OpenCart should be configured to run with the minimum privileges necessary for normal operation.\r\n\r\n### Acknowledgements\r\nThank you to Noah Magill for reporting this vulnerability. This document was written by Bob Kemerer.","title":"Summary"},{"category":"legal_disclaimer","text":"THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. ","title":"Legal Disclaimer"},{"category":"other","text":"CERT/CC Vulnerability Note is a limited advisory. It primarily identifies vendors impacted by the advisory and not specific products. We only support \"known_affected\" and \"known_not_affected\" status. Please consult the vendor's statements and advisory URL if provided by the vendor for more details ","title":"Limitations of Advisory"}],"publisher":{"category":"coordinator","contact_details":"Email: cert@cert.org, Phone: +1412 268 5800","issuing_authority":"CERT/CC under DHS/CISA https://www.cisa.gov/cybersecurity also see https://kb.cert.org/ ","name":"CERT/CC","namespace":"https://kb.cert.org/"},"references":[{"url":"https://certcc.github.io/certcc_disclosure_policy","summary":"CERT/CC vulnerability disclosure policy"},{"summary":"CERT/CC document released","category":"self","url":"https://kb.cert.org/vuls/id/614868"},{"url":"https://github.com/opencart/opencart","summary":"https://github.com/opencart/opencart"},{"url":"https://www.opencart.com/","summary":"https://www.opencart.com/"},{"url":"https://en.wikipedia.org/wiki/Web_shell","summary":"https://en.wikipedia.org/wiki/Web_shell"}],"title":"Opencart ecommerce platform contains directory traversal vulnerability","tracking":{"current_release_date":"2026-08-10T14:47:20+00:00","generator":{"engine":{"name":"VINCE","version":"3.0.43"}},"id":"VU#614868","initial_release_date":"2026-08-10 14:47:20.635341+00:00","revision_history":[{"date":"2026-08-10T14:47:20+00:00","number":"1.20260810144720.1","summary":"Released on 2026-08-10T14:47:20+00:00"}],"status":"final","version":"1.20260810144720.1"}},"vulnerabilities":[{"title":"OpenCart extensions are uploaded as zip files with .","notes":[{"category":"summary","text":"OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these zip files, but does not validate that the extracted paths stay inside the intended extraction directory. An attacker can craft a malicious extension containing file path traversal sequences, such as ../. With this vulnerability, an attacker can write files, such as a PHP web shell, into the webroot directory."}],"cve":"CVE-2026-18412","ids":[{"system_name":"CERT/CC V Identifier ","text":"VU#614868"}]}],"product_tree":{"branches":[]}}