High severity7.2NVD Advisory· Published Jan 26, 2021· Updated Jun 17, 2026
CVE-2021-3291
CVE-2021-3291
Description
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
zencart/zencartPackagist | < 1.5.7c | 1.5.7c |
Affected products
3- Zen Cart/Zen Cartdescription
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/161613/Zen-Cart-1.5.7b-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-38f9-4vhq-9cr8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-3291ghsaADVISORY
- github.com/zencart/zencart/commit/7447627f7148b11c614f89dab4a09d3f102b58afghsaWEB
News mentions
0No linked articles in our index yet.