CVE-2013-1891: Opencart

Medium severity, CVSS 6.5. EPSS: 6.6% chance of exploitation in the next 30 days.

In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.

Affected products

  • Opencart Opencart: from 1.4.7, up to and including 1.5.5.1

Published 2022-06-24. Last modified 2026-06-16.