CVE-2026-108827 | Zen Cart up to 2.2.2 Administrative Module Management general.php zen_call_function use_function code injection (GHSA-xrv3-wg8v-w8q8)

SecurityVulns

A vulnerability was found in Zen Cart up to 2.2.2 and classified as problematic. Affected is the function zen_call_function of the file admin/includes/functions/general.php of the component Administrative Module Management. Executing a manipulation of the argument use_function can lead to code injection.

This vulnerability is tracked as CVE-2026-108827. The attack can be launched remotely. Moreover, an exploit is present.

The vendor explains: “We don’t consider this an independently exploitable vulnerability. The only path to controlling `use_function`/`configuration_value` in the `configuration` table is the SQL Patch tool (raw arbitrary SQL execution) or a pre-existing SQL injection elsewhere”.VulDB Recent EntriesRead More