← Vulnerability feed

Vulnerability record · CVE-2024-5762 · published 21 August 2024

CVE-2024-5762: Zen Cart findPluginAdminPage local file inclusion leads to remote code execution

Zen Cart · Zen Cart

Zen Cart's findPluginAdminPage function passes user-supplied data to a PHP include without proper validation, allowing local file inclusion that can be chained into remote code execution. The flaw is remotely reachable without authentication, so any exposed Zen Cart installation is at risk. It matters because successful exploitation runs attacker code under the service account.

8.1 CVSS 3.1 High EPSS 72% · top 0.6% CWE-98 · PHP remote file inclusionCWE-829 · Inclusion from untrusted sphere
8.1CVSS 3.1 base score
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Zen Cart. Authentication is not required to exploit this vulnerability. The specific flaw exists within the findPluginAdminPage function. The issue results from the lack of proper validation of user-supplied data prior to passing it to a PHP include function. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the service account. Was ZDI-CAN-21408.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable code execution with a high EPSS score, though exploitation requires chaining and no in-the-wild activity is confirmed.

What it is

Zen Cart's findPluginAdminPage function passes user-supplied data to a PHP include without proper validation, allowing local file inclusion that can be chained into remote code execution. The flaw is remotely reachable without authentication, so any exposed Zen Cart installation is at risk. It matters because successful exploitation runs attacker code under the service account.

Impact

An attacker can execute arbitrary code in the context of the Zen Cart service account, potentially leading to full compromise of the web application and its data. The description notes code execution depends on chaining with other vulnerabilities.

Attack surface

Reached over the network via the findPluginAdminPage function; the CVSS vector shows AV:N, PR:N and UI:N, so no authentication or user interaction is required. The record does not specify the exact request path or parameter.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented. EPSS is high at 0.716 (99.4th percentile), but the references are only release notes and a ZDI advisory, with no public exploit or in-the-wild reporting stated.

What to do

  • Apply the Zen Cart 2.0.0 release or later, which the release notes reference as containing the fix.
  • If patching is delayed, restrict network access to the affected Zen Cart admin/plugin functionality and place the site behind authentication or a WAF.
  • Review and harden PHP include paths so user input cannot influence file inclusion.
  • Run the web service under a least-privilege account to limit post-exploitation impact.
  • Monitor vendor and ZDI advisories for updated guidance.

Detection

  • Search web logs for requests to findPluginAdminPage or plugin-related endpoints with unusual file path parameters.
  • Alert on PHP include or file access errors referencing unexpected local paths or remote URLs.
  • Monitor for unexpected child processes or outbound connections spawned by the web server user.
  • Baseline normal plugin admin page requests and flag deviations in parameter values or request frequency.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-5762 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-0697Zen-cart zen cart permissions and access controls vulnerabilityZen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, p…EPSS 5.2%9.8CVE-2015-8352Zen-cart zen cart path traversal vulnerabilityDirectory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ac…EPSS 16%8.8CVE-2017-11675Zen-cart zen cart code injection vulnerabilityThe traverseStrictSanitize function in admin_dir/includes/classes/AdminRequestSanitizer.php in ZenCart 1.5.5e mishandles key strings, which allows re…EPSS 2.9%7.5CVE-2009-4323Zen-cart zen cart vulnerabilityThe installation for Zen Cart stores sensitive information and insecure programs under the (1) docs, (2) extras, and (3) zc_install folders, and (4) …EPSS 2.6%7.5CVE-2009-2254Zen-cart zen cart sql injection vulnerabilityZen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows remote attackers to execute a…EPSS 11%7.5CVE-2008-6615Zen-cart zen cart sql injection vulnerabilitySQL injection vulnerability in index.php in Zen Software Zen Cart 2008 allows remote attackers to execute arbitrary SQL commands via the keyword para…EPSS 0.96%7.2CVE-2021-3291Zen-cart zen cart os command injection vulnerabilityZen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting…EPSS 17%6.8CVE-2008-6985Zen-cart zen cart sql injection vulnerabilityMultiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magic_quotes_gpc is disabled, all…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2024-5762), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.