PT-2026-39526 · Opencart · Opencart

Published

2026-05-10

·

Updated

2026-05-10

·

CVE-2021-47953

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick authenticated users into submitting hidden forms with new password values in the 'password' and 'confirm' parameters to hijack accounts.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2021-47953

Affected Products

Opencart