CVE-2020-28838

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
11/12/2020
Last modified:
15/12/2020

Description

Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items via Add to cart.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opencart:opencart:3.0.3.6:*:*:*:*:*:*:*