PT-2026-39520 · Opencart · Opencart

Published

2026-05-10

·

Updated

2026-05-10

·

CVE-2021-47946

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenCart version 3.0.36
Description A cross-site request forgery (CSRF) issue exists in the "/account/edit" endpoint. This allows unauthenticated attackers to modify account details of victims by tricking them into visiting malicious pages. By crafting CSRF payloads, attackers can change victim email addresses and account information, subsequently using the password reset functionality to gain unauthorized access to the compromised accounts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Weakness Enumeration

Related Identifiers

CVE-2021-47946

Affected Products

Opencart