Description
In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.
Remediation
References
Related Vulnerabilities
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-37911)
MySQL CVE-2023-21976 Vulnerability (CVE-2023-21976)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery SQL Injection (1.3.50)
Drupal CVE-2020-28949 Vulnerability (CVE-2020-28949)
WordPress Plugin Sign-up Sheets Cross-Site Scripting (1.0.13)