Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| zencart/zencart(Packagist) | 0 | 1.5.7c | N/A |
CVSS Metrics