PT-2026-39499 · Opencart · Opencart

Hubert Wojciechowski

·

Published

2026-05-10

·

Updated

2026-05-10

·

CVE-2021-47923

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenCart version 3.0.3.8
Description A session fixation issue exists where attackers can hijack user sessions by injecting arbitrary values into the OCSESSID cookie. The server accepts and maintains these malicious cookie values, which enables session takeover and unauthorized access to user accounts.
Recommendations Update OpenCart version 3.0.3.8 to a patched version.

Exploit

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2021-47923

Affected Products

Opencart