CVE-2015-3301 | TheCartPress eCommerce Shopping Cart up to 1.3.9.2 on WordPress wp-admin/admin.php tcp_box_path path traversal (ID 131673 / EDB-36860)
A vulnerability was found in TheCartPress eCommerce Shopping Cart up to 1.3.9.2 on WordPress and classified as critical. Affected by this issue is some unknown functionality of the file wp-admin/admin.php. The manipulation of the argument tcp_box_path leads to path traversal.
This vulnerability is handled as CVE-2015-3301. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.