Post by faca5 » Tue Jun 17, 2025 5:05 pm

Hello.

Based on the most recently available public information, a new method has been discovered that allows unauthorized access to a user's account.

Because of this, we reported the issue to the admin via PM and prepared a fix for older versions (2.x, 3.x).

More information can be found on link below + path for fix security issue:
https://www.opencart.com/index.php?rout ... n_id=47535
Last edited by faca5 on Tue Jun 17, 2025 9:01 pm, edited 2 times in total.

Izdelava spletne trgovine | Najem spletne trgovine | PHP programiranje


User avatar
New member

Posts

Joined
Wed Aug 27, 2014 7:23 pm


Post by JNeuhoff » Tue Jun 17, 2025 5:33 pm

If there is a security issue, why not publish it, and provide a fix via github, to improve the OpenCart core code?

Export/Import Tool * SpamBot Buster * Unused Images Manager * Instant Option Price Calculator * Number Option * Google Tag Manager * Survey Plus * OpenTwig


User avatar
Guru Member

Posts

Joined
Wed Dec 05, 2007 3:38 am


Post by ADD Creative » Tue Jun 17, 2025 5:49 pm

Looks like the issue I reported in February last year.

Has been patched in 3.0.4.0 and above.
https://github.com/opencart/opencart/pull/13710
https://github.com/opencart/opencart/pull/13714

www.add-creative.co.uk


Guru Member

Posts

Joined
Sat Jan 14, 2012 1:02 am
Location - United Kingdom

Post by ADD Creative » Tue Jun 17, 2025 5:58 pm

Also patched in version 4.1.0.1 and above.
https://github.com/opencart/opencart/co ... 88dfd597cd

www.add-creative.co.uk


Guru Member

Posts

Joined
Sat Jan 14, 2012 1:02 am
Location - United Kingdom

Post by faca5 » Tue Jun 17, 2025 8:55 pm

Excellent.

I have tested on 3.0.3.2. Didn't noted patch already exists in 3.0.4.0 and 4.1.0.1.

Thank you!

Izdelava spletne trgovine | Najem spletne trgovine | PHP programiranje


User avatar
New member

Posts

Joined
Wed Aug 27, 2014 7:23 pm

Who is online

Users browsing this forum: No registered users and 3 guests