Impact
The vulnerability exists in OpenCart’s Autocomplete Workflow, specifically in catalog/controller/account/edit.php. By manipulating the firstname argument, an attacker can inject arbitrary JavaScript, leading to a reflected cross‑site scripting attack.
Affected Systems
OpenCart 4.1.0.3 and 4.1.0.4. These versions contain the vulnerable edit.php file within the Autocomplete Workflow component, and any system running either version is impacted regardless of deployment size or architecture.
Risk and Exploitability
The CVSS score of 5.1 places this issue in the moderate severity range. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack can be initiated remotely, and an exploit has been publicly disclosed, indicating a realistic threat of exploitation. The flaw permits arbitrary JavaScript execution, which is the core of the XSS effect described.
OpenCVE Enrichment