OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the background.
https://github.com/advisories/GHSA-236j-rfx5-wq38
https://medium.com/%40nowczj/sql-injection-exists-in-the-background-of-opencart-d41b5c58e99e