GHSA-3j6m-m5v5-9785

Suggest an improvement
Source
https://github.com/advisories/GHSA-3j6m-m5v5-9785
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-3j6m-m5v5-9785/GHSA-3j6m-m5v5-9785.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3j6m-m5v5-9785
Aliases
Published
2022-05-24T17:36:05Z
Modified
2024-04-23T17:43:53.672289Z
Severity
  • 3.5 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
OpenCart Cross-Site Request Forgery (CSRF)
Details

Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items via Add to cart.

Database specific
{
    "nvd_published_at": "2020-12-11T15:15:00Z",
    "cwe_ids": [
        "CWE-352"
    ],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2024-04-23T17:28:28Z"
}
References

Affected packages

Packagist / opencart/opencart

Package

Name
opencart/opencart
Purl
pkg:composer/opencart/opencart

Affected ranges

Affected versions

3.*

3.0.3.6