Vulnerability record · CVE-2024-5762 · published 21 August 2024
CVE-2024-5762: Zen Cart findPluginAdminPage local file inclusion leads to remote code execution
Zen Cart · Zen Cart
Zen Cart's findPluginAdminPage function passes user-supplied data to a PHP include without proper validation, allowing local file inclusion that can be chained into remote code execution. The flaw is remotely reachable without authentication, so any exposed Zen Cart installation is at risk. It matters because successful exploitation runs attacker code under the service account.
Description
Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Zen Cart. Authentication is not required to exploit this vulnerability. The specific flaw exists within the findPluginAdminPage function. The issue results from the lack of proper validation of user-supplied data prior to passing it to a PHP include function. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the service account. Was ZDI-CAN-21408.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityUnauthenticated network-reachable code execution with a high EPSS score, though exploitation requires chaining and no in-the-wild activity is confirmed.
What it is
Zen Cart's findPluginAdminPage function passes user-supplied data to a PHP include without proper validation, allowing local file inclusion that can be chained into remote code execution. The flaw is remotely reachable without authentication, so any exposed Zen Cart installation is at risk. It matters because successful exploitation runs attacker code under the service account.
Impact
An attacker can execute arbitrary code in the context of the Zen Cart service account, potentially leading to full compromise of the web application and its data. The description notes code execution depends on chaining with other vulnerabilities.
Attack surface
Reached over the network via the findPluginAdminPage function; the CVSS vector shows AV:N, PR:N and UI:N, so no authentication or user interaction is required. The record does not specify the exact request path or parameter.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is high at 0.716 (99.4th percentile), but the references are only release notes and a ZDI advisory, with no public exploit or in-the-wild reporting stated.
What to do
- Apply the Zen Cart 2.0.0 release or later, which the release notes reference as containing the fix.
- If patching is delayed, restrict network access to the affected Zen Cart admin/plugin functionality and place the site behind authentication or a WAF.
- Review and harden PHP include paths so user input cannot influence file inclusion.
- Run the web service under a least-privilege account to limit post-exploitation impact.
- Monitor vendor and ZDI advisories for updated guidance.
Detection
- Search web logs for requests to findPluginAdminPage or plugin-related endpoints with unusual file path parameters.
- Alert on PHP include or file access errors referencing unexpected local paths or remote URLs.
- Monitor for unexpected child processes or outbound connections spawned by the web server user.
- Baseline normal plugin admin page requests and flag deviations in parameter values or request frequency.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://docs.zen-cart.com/release/whatsnew_2.0.0 | Release Notes |
| https://www.zerodayinitiative.com/advisories/ZDI-24-883/ | Third Party AdvisoryVDB Entry |
Track CVE-2024-5762 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-5762), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.