OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick authenticated users into submitting hidden forms with new password values in the 'password' and 'confirm' parameters to hijack accounts.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 10 May 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick authenticated users into submitting hidden forms with new password values in the 'password' and 'confirm' parameters to hijack accounts. | |
| Title | OpenCart 3.0.3.7 Cross-Site Request Forgery via account/password | |
| First Time appeared |
Opencart
Opencart opencart |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:opencart:opencart:3.0.3.7:*:*:*:*:*:*:* | |
| Vendors & Products |
Opencart
Opencart opencart |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-10T12:52:13.172Z
Reserved: 2026-02-01T11:24:18.720Z
Link: CVE-2021-47953
No data.
Status : Received
Published: 2026-05-10T13:16:31.853
Modified: 2026-05-10T13:16:31.853
Link: CVE-2021-47953
No data.
OpenCVE Enrichment
Updated: 2026-05-10T15:30:14Z
Weaknesses