vendor:
Opencart
by:
Hubert Wojciechowski
7.5
CVSS
HIGH
Session Fixation / injection
384
CWE
Product Name: Opencart
Affected Version From: 3.0.3.8
Affected Version To: 3.0.3.8
Patch Exists: NO
Related CWE:
CPE: a:opencart:opencart:3.0.3.8
Platforms Tested: Windows 10
2021
opencart 3.0.3.8 – Sessjion Injection
Session cookie 'OCSESSID' is inproperly processed, allowing an attacker to set any value cookie and server set this value, resulting in a session injection and session fixation vulnerability.
Mitigation:
Ensure that the session cookie is properly validated and sanitized before being used.