First published: Thu Nov 03 2022(Updated: )
OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the background.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/opencart/opencart | <=3.0.3.7 | |
OpenCart | =3.0.3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-37823 is medium with a CVSS score of 4.9.
CVE-2021-37823 affects OpenCart version 3.0.3.7.
CVE-2021-37823 allows users to obtain database information or read server files through SQL injection in the background.
An attacker can exploit CVE-2021-37823 through SQL injection in the background of OpenCart 3.0.3.7.
Yes, upgrading to a patched version of OpenCart, such as version 3.0.3.8, is recommended to fix CVE-2021-37823.