Description
/upload/catalog/controller/account/password.php in OpenCart through 3.0.2.0 has CSRF via the index.php?route=account/password URI to change a user's password.
Remediation
References
Related Vulnerabilities
WordPress Plugin GiveWP-Donation and Fundraising Platform PHP Object Injection (2.3.0)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-3129)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3818)
WordPress Plugin SSL Insecure Content Fixer Information Disclosure (2.0.0)