vendor:
jCart for OpenCart
by:
L0RD
5.5
CVSS
MEDIUM
Cross site request forgery
352
CWE
Product Name: jCart for OpenCart
Affected Version From: 2.3.0.2
Affected Version To: 2.3.0.2
Patch Exists: NO
Related CWE:
CPE: a:joomla:jcart_for_opencart:2.3.0.2
Platforms Tested: Kali linux
2018
Joomla! extension jCart for OpenCart 2.3.0.2 – Cross site request forgery
The Joomla! extension jCart for OpenCart 2.3.0.2 is vulnerable to cross site request forgery. This allows an attacker to change user information, change passwords, and change affiliate account information without proper authentication.
Mitigation:
The vendor should release a patch to fix the vulnerability. In the meantime, users should ensure they have strong passwords and regularly monitor their accounts for any unauthorized changes.