{"id":"GHSA-pgj4-g5j4-cmfx","title":"Withdrawn Advisory: cart2quote/module-quotation-encoded Remote Code Execution via downloadCustomOptionAction","summary":"Withdrawn Advisory: cart2quote/module-quotation-encoded Remote Code Execution via downloadCustomOptionAction","severity":"high","cvss":7,"cwe":["CWE-94"],"vendor":"cart2quote","product":"cart2quote/module-quotation-encoded","ecosystem":"composer","affected":["cart2quote/module-quotation-encoded >= 4.1.6, <= 4.4.5","cart2quote/module-quotation-encoded >= 5.0.0, < 5.4.4","cart2quote/module-quotation >= 4.1.6, < 4.4.6","cart2quote/module-quotation >= 5.0.0, < 5.4.4"],"patched":["cart2quote/module-quotation-encoded 5.4.4","cart2quote/module-quotation 4.4.6","cart2quote/module-quotation 5.4.4"],"published":"2024-05-15","updated":"2026-10-07","sourceUpdated":"2026-10-07T14:00:32Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-pgj4-g5j4-cmfx","references":[{"url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/cart2quote/module-quotation/2017-02-01.yaml"},{"url":"https://web.archive.org/web/20230131172111/https://cart2quote.zendesk.com/hc/en-us/articles/115000616303--FIXED-Security-Vulnerability-in-downloadCustomOptionAction"},{"url":"https://github.com/github/advisory-database/pull/8423"},{"url":"https://cart2quote.zendesk.com/hc/en-us/articles/115000616303--FIXED-Security-Vulnerability-in-downloadCustomOptionAction"},{"url":"https://github.com/advisories/GHSA-pgj4-g5j4-cmfx"}],"tags":["ghsa","composer"],"ingestedAt":"2026-10-07T14:33:21.960Z","slug":"GHSA-pgj4-g5j4-cmfx","body":"## Overview\n\n# Withdrawn Advisory\nThis advisory has been withdrawn because it is specific to the Magento 1 implementation of cart2quote and does not apply to cart2quote/module-quotation-encoded.\n\n# Original Description\ncart2quote/module-quotation-encoded extension may expose a critical security vulnerability by utilizing the unserialize function when processing data from a GET request. This flaw, present in the app/code/community/Ophirah/Qquoteadv/controllers/DownloadController.php and app/code/community/Ophirah/Qquoteadv/Helper/Data.php files, poses a significant risk of Remote Code Execution, especially when custom file options are employed on a product. Attackers exploiting this vulnerability could execute arbitrary code remotely, leading to unauthorized access and potential compromise of sensitive data.\n\n## Affected packages\n\n- `cart2quote/module-quotation-encoded >= 4.1.6, <= 4.4.5`\n- `cart2quote/module-quotation-encoded >= 5.0.0, < 5.4.4`\n- `cart2quote/module-quotation >= 4.1.6, < 4.4.6`\n- `cart2quote/module-quotation >= 5.0.0, < 5.4.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `cart2quote/module-quotation-encoded 5.4.4`\n- `cart2quote/module-quotation 4.4.6`\n- `cart2quote/module-quotation 5.4.4`","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}