PT-2024-18930 · Opencart · Opencart
Calum Hutton
·
Published
2024-06-21
·
Updated
2025-01-14
·
CVE-2024-21517
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
opencart/opencart version 4.0.0.0
Description
A reflected XSS issue was identified in the
redirect parameter of the "customer account/login" route. An attacker can inject arbitrary HTML and Javascript into the page response. This issue is present in the account functionality and could be used to target and attack customers of the OpenCart shop.Recommendations
As a temporary workaround, consider restricting access to the vulnerable
redirect parameter in the customer account/login route until a complete fix is available.
Note: The current fix for this issue is incomplete, so it is essential to monitor for updates and apply a complete fix as soon as it becomes available.
At the moment, there is no information about a newer version that contains a complete fix for this vulnerability.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opencart