Vulnerability Description
Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the product_id parameter. Attackers can craft malicious SQL queries using time-based or content-based blind injection techniques to enumerate usernames, emails, and password reset codes from the oc_user table.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/50493
- https://www.opencartextensions.in/
- https://www.opencartextensions.in/opencart-multi-vendor-multi-seller-marketplace
- https://www.vulncheck.com/advisories/opencart-tmd-vendor-system-3-x-blind-sql-in
FAQ
What is CVE-2021-47928?
CVE-2021-47928 is a vulnerability with a CVSS score of 8.2 (HIGH). Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the product_id parameter...
How severe is CVE-2021-47928?
CVE-2021-47928 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-47928?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.