CVE-2011-4832: Caupo Cauposhop Classic

High severity, CVSS 7.5. EPSS: 2.5% chance of exploitation in the next 30 days.

Directory traversal vulnerability in CaupoShop Pro 2.x, CaupoShop Classic 3.01, and CaupoShop Pro 3.70 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter in a template action.

Affected products

  • Caupo Cauposhop Classic: version 3.01 only
  • Caupo Cauposhop Pro: up to and including 3.70; version 2.0 only; version 2.1 only

Published 2011-12-15. Last modified 2026-06-16.