CVE-2020-20491: Opencart
High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.
SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the Fba plugin function in upload/admin/index.php.
Affected products
- Opencart Opencart: from 2.2.00, up to and including 3.0.3.2
Published 2023-06-20. Last modified 2026-06-17.