---
id: GHSA-pgj4-g5j4-cmfx
title: >-
  Withdrawn Advisory: cart2quote/module-quotation-encoded Remote Code Execution
  via downloadCustomOptionAction
summary: >-
  Withdrawn Advisory: cart2quote/module-quotation-encoded Remote Code Execution
  via downloadCustomOptionAction
severity: high
cvss: 7
cwe:
  - CWE-94
vendor: cart2quote
product: cart2quote/module-quotation-encoded
ecosystem: composer
affected:
  - 'cart2quote/module-quotation-encoded >= 4.1.6, <= 4.4.5'
  - 'cart2quote/module-quotation-encoded >= 5.0.0, < 5.4.4'
  - 'cart2quote/module-quotation >= 4.1.6, < 4.4.6'
  - 'cart2quote/module-quotation >= 5.0.0, < 5.4.4'
patched:
  - cart2quote/module-quotation-encoded 5.4.4
  - cart2quote/module-quotation 4.4.6
  - cart2quote/module-quotation 5.4.4
published: '2024-05-15'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T14:00:32Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-pgj4-g5j4-cmfx'
references:
  - url: >-
      https://github.com/FriendsOfPHP/security-advisories/blob/master/cart2quote/module-quotation/2017-02-01.yaml
  - url: >-
      https://web.archive.org/web/20230131172111/https://cart2quote.zendesk.com/hc/en-us/articles/115000616303--FIXED-Security-Vulnerability-in-downloadCustomOptionAction
  - url: 'https://github.com/github/advisory-database/pull/8423'
  - url: >-
      https://cart2quote.zendesk.com/hc/en-us/articles/115000616303--FIXED-Security-Vulnerability-in-downloadCustomOptionAction
  - url: 'https://github.com/advisories/GHSA-pgj4-g5j4-cmfx'
tags:
  - ghsa
  - composer
ingestedAt: '2026-10-07T14:33:21.960Z'
---

## Overview

# Withdrawn Advisory
This advisory has been withdrawn because it is specific to the Magento 1 implementation of cart2quote and does not apply to cart2quote/module-quotation-encoded.

# Original Description
cart2quote/module-quotation-encoded extension may expose a critical security vulnerability by utilizing the unserialize function when processing data from a GET request. This flaw, present in the app/code/community/Ophirah/Qquoteadv/controllers/DownloadController.php and app/code/community/Ophirah/Qquoteadv/Helper/Data.php files, poses a significant risk of Remote Code Execution, especially when custom file options are employed on a product. Attackers exploiting this vulnerability could execute arbitrary code remotely, leading to unauthorized access and potential compromise of sensitive data.

## Affected packages

- `cart2quote/module-quotation-encoded >= 4.1.6, <= 4.4.5`
- `cart2quote/module-quotation-encoded >= 5.0.0, < 5.4.4`
- `cart2quote/module-quotation >= 4.1.6, < 4.4.6`
- `cart2quote/module-quotation >= 5.0.0, < 5.4.4`

## Remediation

Upgrade to a patched release:

- `cart2quote/module-quotation-encoded 5.4.4`
- `cart2quote/module-quotation 4.4.6`
- `cart2quote/module-quotation 5.4.4`
