Cross-Site Request Forgery in OpenCart Product by OpenCart
CVE-2018-13067
8.8HIGH
What is CVE-2018-13067?
A vulnerability exists in OpenCart affecting versions through 3.0.2.0, where improper validation of requests allows attackers to exploit the password change functionality. This is achieved through the index.php?route=account/password endpoint, enabling unauthorized users to change legitimate user passwords without proper validation, thereby compromising user accounts.