CVE-2026-5331 identifies a path traversal vulnerability in OpenCart version 4.1.0.3, specifically within the installer.php file of the Extension Installer Page component. Rated Medium with a CVSSv3.1 score of 4.7, this vulnerability allows a remote attacker with high privileges to manipulate the file system, leading to low impacts on confidentiality, integrity, and availability. The exploit has been publicly disclosed, though it is not currently listed on the CISA KEV catalog and lacks readily available exploit modules in Metasploit, Nuclei, or ExploitDB. The vendor has not responded to the disclosure, and community discussion is minimal, with only one known mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | OpenCart | 4.1.0.3CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.