CVE-2021-47946: OpenCart 3.0.3.6 Account Takeover via Cross Site Request Forgery
OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthenticated attackers to modify victim account details by tricking users into visiting malicious pages. Attackers can craft CSRF payloads that change victim email addresses and account information, then use password reset functionality to gain unauthorized access to compromised accounts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47946?
CVE-2021-47946 is classified as a high severity vulnerability due to its potential for account takeover via cross-site request forgery.
How do I fix CVE-2021-47946?
To fix CVE-2021-47946, upgrade to a patched version of OpenCart that addresses this vulnerability, specifically version 3.0.37 or higher.
What kind of attacks can exploit CVE-2021-47946?
CVE-2021-47946 can be exploited through cross-site request forgery where attackers trick users into visiting malicious pages to modify account details.
Who is affected by CVE-2021-47946?
CVE-2021-47946 affects users of OpenCart version 3.0.36 specifically.
What impact does CVE-2021-47946 have on users?
The impact of CVE-2021-47946 includes unauthorized modification of user account details, potentially leading to account takeover.