VYPR
High severity8.1NVD Advisory· Published Sep 27, 2023· Updated Jun 17, 2026

CVE-2023-2315

CVE-2023-2315

Description

Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the Log component to empty out arbitrary files on the server

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
opencart/opencartPackagist
>= 4.0.0.0, < 4.0.2.34.0.2.3

Affected products

3
  • Opencart/Opencart2 versions
    cpe:2.3:a:opencart:opencart:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:opencart:opencart:*:*:*:*:*:*:*:*range: >=4.0.0.0,<=4.0.2.2
    • (no CPE)range: 4.0.0.0
  • ghsa-coords
    Range: >= 4.0.0.0, < 4.0.2.3

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.