OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick authenticated users into submitting hidden forms with new password values in the 'password' and 'confirm' parameters to hijack accounts.
Metrics
Affected Vendors & Products
References
History
Sun, 10 May 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick authenticated users into submitting hidden forms with new password values in the 'password' and 'confirm' parameters to hijack accounts. | |
| Title | OpenCart 3.0.3.7 Cross-Site Request Forgery via account/password | |
| First Time appeared |
Opencart
Opencart opencart |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:opencart:opencart:3.0.3.7:*:*:*:*:*:*:* | |
| Vendors & Products |
Opencart
Opencart opencart |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-10T12:52:13.172Z
Reserved: 2026-02-01T11:24:18.720Z
Link: CVE-2021-47953
No data.
Status : Received
Published: 2026-05-10T13:16:31.853
Modified: 2026-05-10T13:16:31.853
Link: CVE-2021-47953
No data.
OpenCVE Enrichment
Updated: 2026-05-10T15:30:14Z