Junglewise Threat Intelligence

CVE-2021-47946: OpenCart CSRF in account edit endpoint

CVE-2021-47946 · Severity: medium · CVSS 5.3 · Published 2026-05-10

Technologies: OpenCart. Vendors: OpenCart.

Executive brief

OpenCart, a popular open-source e-commerce platform, is vulnerable to a security flaw that allows attackers to take over customer accounts. By tricking a logged-in user into visiting a malicious website, an attacker can silently change the user's email address and account details. Once the email is changed, the attacker can use the standard password reset feature to gain full control of the account, potentially accessing personal data and order history.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in OpenCart versions up to and including 3.0.3.6 within the '/account/edit' endpoint. The application fails to properly validate CSRF tokens when updating user profile information. An unauthenticated remote attacker can exploit this by inducing a logged-in user to visit a malicious webpage containing a crafted payload. This payload can modify the victim's account details, specifically the registered email address. Once the email is changed to one controlled by the attacker, they can initiate a password reset to achieve full account takeover. Proof-of-concept exploits have been publicly disclosed.

Affected products

  • OpenCart OpenCart <= 3.0.3.6

Timeline

  • 2021-01-09: disclosed: Original discovery and exploit publication by Mahendra Purbia
  • 2026-05-10: advisory: NVD/VulnCheck advisory published

References

Related threats