CVE-2021-47923
CRITICALOpenCart 3.0.3.8 Session Fixation via OCSESSID Cookie
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47923. PoCs published by Hubert Wojciechowski.
AI-analyzed exploit summary The exploit demonstrates a session fixation/injection vulnerability in OpenCart 3.0.3.8 by showing how an attacker can set an arbitrary value for the 'OCSESSID' cookie, which the server then accepts and reflects back. This allows for session hijacking or fixation attacks.
Description
OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSESSID cookie. Attackers can set malicious OCSESSID cookie values that the server accepts and maintains, enabling session takeover and unauthorized access to user accounts.
Exploits (1)
The exploit demonstrates a session fixation/injection vulnerability in OpenCart 3.0.3.8 by showing how an attacker can set an arbitrary value for the 'OCSESSID' cookie, which the server then accepts and reflects back. This allows for session hijacking or fixation attacks.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H