Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 11 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 10 May 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick authenticated users into submitting hidden forms with new password values in the 'password' and 'confirm' parameters to hijack accounts. | |
| Title | OpenCart 3.0.3.7 Cross-Site Request Forgery via account/password | |
| First Time appeared |
Opencart
Opencart opencart |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:opencart:opencart:3.0.3.7:*:*:*:*:*:*:* | |
| Vendors & Products |
Opencart
Opencart opencart |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-11T16:02:16.127Z
Reserved: 2026-02-01T11:24:18.720Z
Link: CVE-2021-47953
Updated: 2026-05-11T16:01:52.780Z
Status : Deferred
Published: 2026-05-10T13:16:31.853
Modified: 2026-05-12T14:24:15.210
Link: CVE-2021-47953
No data.
OpenCVE Enrichment
Updated: 2026-05-10T15:30:14Z