VDB

CVE-2022-24108

CVE-2022-24108 PUBLISHED CVSS 9.800000190734863 CRITICAL

The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting parameter, potentially resulting in the ability to write to files on the server, cause DoS, and achieve remote code execution because of deserialization of untrusted data.

EPSS 32.61% · 98.2th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
32.61%
98.2th percentile

Affected Products

VendorProductVersions
n/an/an/a
skyoftechso_listing_tabs2.2.0

Timeline

  • May 17, 2022 PoC Published
  • May 17, 2022 CVE Published
  • May 18, 2022 EPSS Score
  • Jul 6, 2022 EPSS Score
  • Aug 25, 2022 EPSS Score
  • Dec 1, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 27, 2023 EPSS Score
  • May 24, 2023 EPSS Score
  • Aug 4, 2023 EPSS Score
  • Nov 10, 2023 EPSS Score
  • Jan 6, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›