{"id":"GHSA-pgj4-g5j4-cmfx","aliases":[],"url":"https://o3.security/vulnerability/GHSA-pgj4-g5j4-cmfx","summary":"cart2quote/module-quotation-encoded Remote Code Execution via downloadCustomOptionAction","details":"cart2quote/module-quotation-encoded extension may expose a critical security vulnerability by utilizing the unserialize function when processing data from a GET request. This flaw, present in the app/code/community/Ophirah/Qquoteadv/controllers/DownloadController.php and app/code/community/Ophirah/Qquoteadv/Helper/Data.php files, poses a significant risk of Remote Code Execution, especially when custom file options are employed on a product. Attackers exploiting this vulnerability could execute arbitrary code remotely, leading to unauthorized access and potential compromise of sensitive data. ","published":"2024-05-15T18:06:58Z","modified":"2026-09-10T03:50:14.113949372Z","cvss":{"score":7,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"cart2quote/module-quotation-encoded","fixedVersion":null},{"ecosystem":"Packagist","name":"cart2quote/module-quotation-encoded","fixedVersion":"5.4.4"}],"fix":null,"references":[{"type":"PACKAGE","url":"https://bitbucket.org/cart2quote2/cart2quote2-releases"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/cart2quote/module-quotation/2017-02-01.yaml"},{"type":"WEB","url":"https://web.archive.org/web/20230131172111/https://cart2quote.zendesk.com/hc/en-us/articles/115000616303--FIXED-Security-Vulnerability-in-downloadCustomOptionAction"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:14.113949372Z"}}