{"id":"CVE-2021-3291","details":"Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.","aliases":["GHSA-38f9-4vhq-9cr8"],"modified":"2026-07-09T00:05:52.271177Z","published":"2021-01-26T18:16:29.677Z","references":[{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/161613/Zen-Cart-1.5.7b-Remote-Code-Execution.html"},{"type":"EVIDENCE","url":"https://github.com/MucahitSaratar/zencart_auth_rce_poc"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zencart/zencart","events":[{"introduced":"a57158b8c80f27e61720a5fc9eb24141ff0a180c"},{"last_affected":"a57158b8c80f27e61720a5fc9eb24141ff0a180c"}],"database_specific":{"cpe":"cpe:2.3:a:zen-cart:zen_cart:1.5.7b:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.5.7b"},{"last_affected":"1.5.7b"}],"source":"CPE_STRING"}}],"versions":["1.5.7b","v1.5.7d"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3291.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}