Vulnerability Description
OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick authenticated users into submitting hidden forms with new password values in the 'password' and 'confirm' parameters to hijack accounts.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/49970
- https://www.vulncheck.com/advisories/opencart-cross-site-request-forgery-via-acc
FAQ
What is CVE-2021-47953?
CVE-2021-47953 is a vulnerability with a CVSS score of 4.3 (MEDIUM). OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick au...
How severe is CVE-2021-47953?
CVE-2021-47953 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-47953?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.