Description
OpenCart through 3.0.2.0 allows directory traversal in the editDownload function in admin\model\catalog\download.php via admin/index.php?route=catalog/download/edit, related to the download_id. For example, an attacker can download ../../config.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin WPML Translation Management PHP Object Injection (2.4.1)
OpenSSL Cryptographic Issues Vulnerability (CVE-2014-8275)
WordPress Plugin Amazon Tools Cross-Site Scripting (1.7.2)
WebLogic CVE-2022-21347 Vulnerability (CVE-2022-21347)
WordPress Plugin Premmerce Wishlist for WooCommerce Security Bypass (1.1.2)