First published: Tue Jan 12 2016(Updated: )
Cross-site scripting (XSS) vulnerability in OpenCart before 2.1.0.2 allows remote attackers to inject arbitrary web script or HTML via the zone_id parameter to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenCart | <=2.1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4671 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
To fix CVE-2015-4671, update OpenCart to version 2.1.0.2 or later to mitigate the XSS vulnerability.
CVE-2015-4671 affects all versions of OpenCart prior to 2.1.0.2.
Attackers can use CVE-2015-4671 to inject arbitrary web scripts or HTML into web pages, potentially compromising user data.
Yes, CVE-2015-4671 can be easily exploited by an attacker through manipulation of the zone_id parameter.