Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-01-26T06:47:35

Updated: 2021-03-02T17:06:27

Reserved: 2021-01-25T00:00:00


Link: CVE-2021-3291

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-01-26T18:16:29.677

Modified: 2021-03-09T21:34:32.547


Link: CVE-2021-3291

JSON object: View

cve-icon Redhat Information

No data.

CWE