asaanCart could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL request to the index.php script using the page parameter, to specify a malicious file from the local system, which could allow the attacker to obtain sensitive information or execute arbitrary code on the vulnerable Web server.
Vendor Status:
Currently we are not aware of any vendor-supplied patches.