**Notes:**
1) The fix for this vulnerability is incomplete
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2138 | This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the redirect parameter of customer account/login route. An attacker can inject arbitrary HTML and Javascript into the page response. As this vulnerability is present in the account functionality it could be used to target and attack customers of the OpenCart shop. **Notes:** 1) The fix for this vulnerability is incomplete |
Github GHSA |
GHSA-qc3q-8rr8-8p5v | Cross site scripting in opencart |
Tue, 14 Jan 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-01-14T16:25:06.844Z
Reserved: 2023-12-22T12:33:20.120Z
Link: CVE-2024-21517
Updated: 2024-08-01T22:20:40.969Z
Status : Modified
Published: 2024-06-22T05:15:11.173
Modified: 2026-04-29T01:00:01.613
Link: CVE-2024-21517
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA