EIP-2026-110261
PRE-CVEOpenCart - Cross-Site Request Forgery (Change User Password)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110261. PoCs published by Saadi Siddiqui.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in OpenCart, allowing an attacker to change a user's password by tricking them into submitting a crafted form. The PoC includes a malicious HTML form and HTTP request details showing the lack of CSRF tokens in OpenCart's password change functionality.
Description
OpenCart - Cross-Site Request Forgery (Change User Password)
Exploits (1)
This exploit demonstrates a CSRF vulnerability in OpenCart, allowing an attacker to change a user's password by tricking them into submitting a crafted form. The PoC includes a malicious HTML form and HTTP request details showing the lack of CSRF tokens in OpenCart's password change functionality.