CVE-2019-15081: XSS
OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Product, and Information pages.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this OpenCart vulnerability?
The vulnerability ID of this OpenCart vulnerability is CVE-2019-15081.
What is the severity of CVE-2019-15081?
The severity of CVE-2019-15081 is medium with a severity value of 4.8.
What is the affected software for CVE-2019-15081?
The affected software for CVE-2019-15081 is OpenCart 3.x.
How does CVE-2019-15081 work?
CVE-2019-15081 allows an attacker with login access to the OpenCart admin panel to perform stored cross-site scripting (XSS) attacks through the Source/HTML editing feature of the Categories, Product, and Information pages.
Are there any available fixes for CVE-2019-15081?
At the moment, there are no specific fixes available for CVE-2019-15081. It is recommended to apply security best practices and keep the OpenCart software up to date to mitigate the risk.