vendor:
OpenCart
by:
Saadat Ullah
7,5
CVSS
HIGH
Cross-site request forgery
352
CWE
Product Name: OpenCart
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Apache/2.2.15 PHP/5.3.3
2013
OpenCart CSRF
OpenCart is an open source shoping cart system, suffers from Cross-site request forgery through which attacker can manipulate user data via sending him malicious craft url. OpenCart is not using any security token to prevent it against CSRF. It is vulnerable to all location inside User panel.
Mitigation:
Implement security tokens to prevent CSRF attacks.