peter bassill · operator
$ cve CVE-2022-24108 JSON

CVE-2022-24108

9.8
CRITICAL · CVSS 3.1 · EPSS 32.6% (pctl 98)

Patch early

EPSS 32.6% — above the 10% action threshold.

Description

The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting parameter, potentially resulting in the ability to write to files on the server, cause DoS, and achieve remote code execution because of deserialization of untrusted data.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS32.61% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2022-05-17
Last modified2026-06-17

Affected (1)

VendorProduct
skyoftechso listing tabs

References

→ the Explorer  ·  watch your stack  ·  NVD