A AegiFlow
HIGHCVSS 8.4EPSS 0.6%

CVE-2024-53412

NietThijmen ShoppingCart: Command injection in the connect function

Published
2026-04-15
Modified
2026-07-21
EPSS percentile
43%
Aliases
GHSA-ggmw-mjhv-75rm
Sources
github-advisory

Summary

Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection of malicious payloads into the Port field

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/NietThijmen/ShoppingCart

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.