CVE-2021-47923: OpenCart 3.0.3.8 Session Fixation via OCSESSID Cookie
Published May 10, 2026
·Updated
OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSESSID cookie. Attackers can set malicious OCSESSID cookie values that the server accepts and maintains, enabling session takeover and unauthorized access to user accounts.
Affected Software
1 affected component
OpenCart OpenCart=3.0.3.8
Event History
May 10, 2026
CVE Published
via MITRE·12:43 PM
Data Sourced
via MITRE·12:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-47923?
CVE-2021-47923 is considered a medium severity vulnerability due to its potential to allow session hijacking.
2
How do I fix CVE-2021-47923?
To fix CVE-2021-47923, upgrade OpenCart to a version later than 3.0.3.8.
3
What type of vulnerability is CVE-2021-47923?
CVE-2021-47923 is a session fixation vulnerability affecting OpenCart.
4
Who is affected by CVE-2021-47923?
CVE-2021-47923 specifically affects users of OpenCart version 3.0.3.8.
5
What can attackers do with CVE-2021-47923?
Attackers can hijack user sessions by injecting arbitrary values into the OCSESSID cookie.