GHSA-pgj4-g5j4-cmfxHigh· 7.0▾ TwilightWithdrawn Advisory: cart2quote/module-quotation-encoded Remote Code Execution via downloadCustomOptionAction
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is specific to the Magento 1 implementation of cart2quote and does not apply to cart2quote/module-quotation-encoded.
cart2quote/module-quotation-encoded extension may expose a critical security vulnerability by utilizing the unserialize function when processing data from a GET request. This flaw, present in the app/code/community/Ophirah/Qquoteadv/controllers/DownloadController.php and app/code/community/Ophirah/Qquoteadv/Helper/Data.php files, poses a significant risk of Remote Code Execution, especially when custom file options are employed on a product. Attackers exploiting this vulnerability could execute arbitrary code remotely, leading to unauthorized access and potential compromise of sensitive data.
cart2quote/module-quotation-encoded >= 4.1.6, <= 4.4.5cart2quote/module-quotation-encoded >= 5.0.0, < 5.4.4cart2quote/module-quotation >= 4.1.6, < 4.4.6cart2quote/module-quotation >= 5.0.0, < 5.4.4Upgrade to a patched release:
cart2quote/module-quotation-encoded 5.4.4cart2quote/module-quotation 4.4.6cart2quote/module-quotation 5.4.4Connected by shared product, vendor, weakness, or advisory.
CVE-2025-15148Medium· 4.7A flaw has been found in CmsEasy up to 7.7.7
CVE-2025-10097Medium· 6.3A vulnerability was identified in SimStudioAI sim up to 1.0.0
CVE-2025-15394Medium· 4.7A vulnerability was detected in iCMS up to 8.0.0
CVE-2025-15393Medium· 6.3A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135
CVE-2025-13786High· 7.3A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665
CVE-2022-34821High· 7.6A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2), SCALANCE M804PB (6GK5804-0AP00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2), SCALANCE …