CVE-2021-47923

CRITICAL

OpenCart 3.0.3.8 Session Fixation via OCSESSID Cookie

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47923. PoCs published by Hubert Wojciechowski.

AI-analyzed exploit summary The exploit demonstrates a session fixation/injection vulnerability in OpenCart 3.0.3.8 by showing how an attacker can set an arbitrary value for the 'OCSESSID' cookie, which the server then accepts and reflects back. This allows for session hijacking or fixation attacks.

Description

OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSESSID cookie. Attackers can set malicious OCSESSID cookie values that the server accepts and maintains, enabling session takeover and unauthorized access to user accounts.

Exploits (1)

exploitdb WORKING POC
by Hubert Wojciechowski · textwebappsphp
https://www.exploit-db.com/exploits/50555

The exploit demonstrates a session fixation/injection vulnerability in OpenCart 3.0.3.8 by showing how an attacker can set an arbitrary value for the 'OCSESSID' cookie, which the server then accepts and reflects back. This allows for session hijacking or fixation attacks.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: OpenCart 3.0.3.8
No auth needed
Prerequisites: Ability to send HTTP requests with modified cookies
devstral-2 · analyzed May 10, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-50555
https://www.exploit-db.com/exploits/50555
Product product
Official Product Homepage
https://www.opencart.com/
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenCart 3.0.3.8 Session Fixation via OCSESSID Cookie
https://www.vulncheck.com/advisories/opencart-session-fixation-via-ocsessid-cookie

Scores

CVSS v3 9.8
EPSS 0.0042
EPSS Percentile 33.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-290
Status published
Products (1)
Opencart/opencart 3.0.3.8
Published May 10, 2026
Tracked Since May 10, 2026