Settings

Theme

OpenCart owner turns air blue after researcher discloses serious vuln

theregister.com

12 points by rhd 2 years ago · 7 comments

Reader

butz 2 years ago

"turn the air blue": to swear a lot (= use rude words), or to involve a lot of swearing

josephcsible 2 years ago

So the "vulnerability" requires the attacker to already have admin privileges? Then the OpenCart maintainer is right, and the reporters and this article are wrong.

  • nerdawson 2 years ago

    The researcher correctly pointed out that you don't have to be an admin in order to exploit this vulnerability.

    The example given was "Sales" role users who should only ever have limited access to the admin panel.

    > You are taking for granted that end users in the "admin" area are all admins, but it is not always true for other installations. I tested different versions of OpenCart for some clients I work for, where they created multiple "sales" users with different roles, which were not admins but only non-technical people with an account provided to update price info and products. Upset employees, phished users, XSS, etc. are all possibilities that make the exploitation feasible in this case and allow unauthorized users (the sales guys or whoever uses their account) to execute arbitrary commands on the server, which should never be the case with the roles they were provided.

    • josephcsible 2 years ago

      It sounds to me like the sales users have full admin access, and just don't need most of the access that they have. If that's the case, then this still isn't a vulnerability, but I admit it would be one otherwise.

      • nerdawson 2 years ago

        The reference to roles left me with the impression that these users had limited permissions but I know nothing about OpenCart so I may be mistaken.

  • TechSupportJosh 2 years ago

    Until any vulnerability comes along that allows someone to escalate privileges...

    • josephcsible 2 years ago

      But then that would be the vulnerability that needs to be fixed, not this one. That's like saying it's a vulnerability that root can make systemwide changes, since there could be another vulnerability that lets users escalate to root.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection