CVE-2021-47953

MEDIUM

OpenCart 3.0.3.7 Cross-Site Request Forgery via account/password

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47953. PoCs published by Mert Daş.

AI-analyzed exploit summary This is a functional CSRF exploit for OpenCart 3.0.3.7 that demonstrates how an attacker can change a user's password by tricking them into submitting a crafted form. The exploit includes a Burp Suite-generated PoC HTML form and the raw HTTP request/response demonstrating the vulnerability.

Description

OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick authenticated users into submitting hidden forms with new password values in the 'password' and 'confirm' parameters to hijack accounts.

Exploits (1)

exploitdb WORKING POC
by Mert Daş · htmlwebappsphp
https://www.exploit-db.com/exploits/49970

This is a functional CSRF exploit for OpenCart 3.0.3.7 that demonstrates how an attacker can change a user's password by tricking them into submitting a crafted form. The exploit includes a Burp Suite-generated PoC HTML form and the raw HTTP request/response demonstrating the vulnerability.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: OpenCart 3.0.3.7
No auth needed
Prerequisites: Victim must be logged into OpenCart · Victim must visit the malicious HTML page
devstral-2 · analyzed May 10, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit exploit
ExploitDB-49970
https://www.exploit-db.com/exploits/49970
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenCart 3.0.3.7 Cross-Site Request Forgery via account/password
https://www.vulncheck.com/advisories/opencart-cross-site-request-forgery-via-account-password

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 8.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
Opencart/OpenCart 3.0.3.7
Published May 10, 2026
Tracked Since May 10, 2026