First published: Thu Aug 15 2019(Updated: )
OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Product, and Information pages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenCart | >=3.0.0.0<=3.0.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this OpenCart vulnerability is CVE-2019-15081.
The severity of CVE-2019-15081 is medium with a severity value of 4.8.
The affected software for CVE-2019-15081 is OpenCart 3.x.
CVE-2019-15081 allows an attacker with login access to the OpenCart admin panel to perform stored cross-site scripting (XSS) attacks through the Source/HTML editing feature of the Categories, Product, and Information pages.
At the moment, there are no specific fixes available for CVE-2019-15081. It is recommended to apply security best practices and keep the OpenCart software up to date to mitigate the risk.