PT-2019-13973 · Opencart · Opencart

Nipunsomani

·

Published

2019-08-15

·

Updated

2023-03-02

·

CVE-2019-15081

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenCart versions 3.x
Description The issue allows stored XSS within the Source/HTML editing feature of the Categories, Product, and Information pages when an attacker has login access to the admin panel.
Recommendations For OpenCart version 3.x, update to a version that includes a fix for this issue, as no specific workaround is provided for this version.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-15081

Affected Products

Opencart