BIT-opencart-2024-21517

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/opencart/BIT-opencart-2024-21517.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-opencart-2024-21517
Aliases
Published
2024-06-25T11:58:07.173Z
Modified
2024-11-27T19:40:48.342Z
Summary
[none]
Details

This affects versions of the package opencart/opencart from 4.0.0-0. A reflected XSS issue was identified in the redirect parameter of customer account/login route. An attacker can inject arbitrary HTML and Javascript into the page response. As this vulnerability is present in the account functionality it could be used to target and attack customers of the OpenCart shop.

Notes:

1) The fix for this vulnerability is incomplete

Database specific
{
    "cpes": [
        "cpe:2.3:a:opencart:opencart:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / opencart

Package

Name
opencart
Purl
pkg:bitnami/opencart

Severity

  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0-0