CVE-2021-37823: SQL Injection
Published Nov 3, 2022
·Updated
OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the background.
Affected Software
2 affected components
composer/opencart/opencart<=3.0.3.7
OpenCart opencart=3.0.3.7
Event History
Nov 3, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
07:00 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-37823?
The severity of CVE-2021-37823 is medium with a CVSS score of 4.9.
2
How does CVE-2021-37823 affect OpenCart?
CVE-2021-37823 affects OpenCart version 3.0.3.7.
3
What is the vulnerability description of CVE-2021-37823?
CVE-2021-37823 allows users to obtain database information or read server files through SQL injection in the background.
4
How can an attacker exploit CVE-2021-37823?
An attacker can exploit CVE-2021-37823 through SQL injection in the background of OpenCart 3.0.3.7.
5
Is there a fix available for CVE-2021-37823?
Yes, upgrading to a patched version of OpenCart, such as version 3.0.3.8, is recommended to fix CVE-2021-37823.