vendor:
Opencart
by:
Todor Donev
7.5
CVSS
HIGH
Denial of Service (DoS)
400
CWE
Product Name: Opencart
Affected Version From: 3.0.2.0
Affected Version To: 3.0.2.0
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2018
Opencart <= 3.0.2.0 google_sitemap Remote Denial of Service (resource exhaustion)
This exploit is a proof of concept for a resource exhaustion vulnerability in Opencart version 3.0.2.0 and below. The exploit works by sending multiple requests to the google_sitemap route, which can cause the server to become overloaded and unresponsive.
Mitigation:
Upgrade to the latest version of Opencart, which is not vulnerable to this exploit.