{"api_version":"1","generated_at":"2026-07-23T13:09:47+00:00","cve":"CVE-2022-24108","urls":{"html":"https://cve.report/CVE-2022-24108","api":"https://cve.report/api/cve/CVE-2022-24108.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-24108","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-24108"},"summary":{"title":"CVE-2022-24108","description":"The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting parameter, potentially resulting in the ability to write to files on the server, cause DoS, and achieve remote code execution because of deserialization of untrusted data.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2022-05-17 16:15:00","updated_at":"2022-05-26 22:05:00"},"problem_types":["CWE-502"],"metrics":[],"references":[{"url":"https://codecanyon.net/item/so-listing-tabs-responsive-opencart-module/12388133","name":"https://codecanyon.net/item/so-listing-tabs-responsive-opencart-module/12388133","refsource":"MISC","tags":[],"title":"So Listing Tabs - Responsive OpenCart 3.0.x & OpenCart 2.x Module by skyoftech","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://seclists.org/fulldisclosure/2022/May/30","name":"https://seclists.org/fulldisclosure/2022/May/30","refsource":"MISC","tags":[],"title":"Full Disclosure: CVE-2022-24108: OpenCart's plugin \"So Listing Tabs\" <= 2.2.0 Deserialization of Untrusted Data","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.smartaddons.com/opencart-extensions/so-listing-tabs-responsive-opencart-30x-opencart-2x-module","name":"https://www.smartaddons.com/opencart-extensions/so-listing-tabs-responsive-opencart-30x-opencart-2x-module","refsource":"MISC","tags":[],"title":"Responsive OpenCart 3.0.x & OpenCart 2.x Module - So Listing Tabs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/167197/OpenCart-So-Listing-Tabs-2.2.0-Unsafe-Deserialization.html","name":"http://packetstormsecurity.com/files/167197/OpenCart-So-Listing-Tabs-2.2.0-Unsafe-Deserialization.html","refsource":"MISC","tags":[],"title":"OpenCart So Listing Tabs 2.2.0 Unsafe Deserialization ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-24108","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24108","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"24108","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"skyoftech","cpe5":"so_listing_tabs","cpe6":"2.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"opencart","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2022-24108","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting parameter, potentially resulting in the ability to write to files on the server, cause DoS, and achieve remote code execution because of deserialization of untrusted data."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.smartaddons.com/opencart-extensions/so-listing-tabs-responsive-opencart-30x-opencart-2x-module","refsource":"MISC","name":"https://www.smartaddons.com/opencart-extensions/so-listing-tabs-responsive-opencart-30x-opencart-2x-module"},{"url":"https://codecanyon.net/item/so-listing-tabs-responsive-opencart-module/12388133","refsource":"MISC","name":"https://codecanyon.net/item/so-listing-tabs-responsive-opencart-module/12388133"},{"refsource":"MISC","name":"https://seclists.org/fulldisclosure/2022/May/30","url":"https://seclists.org/fulldisclosure/2022/May/30"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/167197/OpenCart-So-Listing-Tabs-2.2.0-Unsafe-Deserialization.html","url":"http://packetstormsecurity.com/files/167197/OpenCart-So-Listing-Tabs-2.2.0-Unsafe-Deserialization.html"}]}},"nvd":{"publishedDate":"2022-05-17 16:15:00","lastModifiedDate":"2022-05-26 22:05:00","problem_types":["CWE-502"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:skyoftech:so_listing_tabs:2.2.0:*:*:*:*:opencart:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2022","CveId":"24108","Ordinal":"227320","Title":"CVE-2022-24108","CVE":"CVE-2022-24108","Year":"2022"},"notes":[{"CveYear":"2022","CveId":"24108","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}