Description
In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.
Remediation
References
Related Vulnerabilities
PHP Improper Input Validation Vulnerability (CVE-2007-4784)
WordPress 5.0.x Cross-Site Request Forgery (5.0 - 5.0.3)
Squid Uncontrolled Resource Consumption Vulnerability (CVE-2021-46784)
OpenSSL Cryptographic Issues Vulnerability (CVE-2011-4576)
Drupal Core 5.x Multiple Cross-Site Request Forgery Vulnerabilities (5.0 - 5.1)