Impact
OpenCart 3.0.3.6 contains a cross‑site request forgery vulnerability in the /account/edit endpoint that allows an unauthenticated attacker to modify a victim’s account details, including the email address, by tricking the user into visiting a malicious page. The attacker can then trigger the password‑reset function to obtain unauthorized access to the compromised account, enabling a full account takeover.
Affected Systems
The vulnerability affects OpenCart installations running version 3.0.3.6. All sites using this version are potentially compromised, regardless of custom extensions, unless a later patch has been applied.
Risk and Exploitability
The CVSS score of 6.9 classifies the flaw as moderate severity. The EPSS score is reported as less than 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploitation at the time of analysis. The attack requires only a malicious link to be visited by an authenticated user, making the exploitation path straightforward with no privileged access or technical barrier. The primary attack vector is a CSRF request.
OpenCVE Enrichment