Description
/upload/catalog/controller/account/password.php in OpenCart through 3.0.2.0 has CSRF via the index.php?route=account/password URI to change a user's password.
Remediation
References
Related Vulnerabilities
WordPress 5.1.x Multiple Vulnerabilities (5.1 - 5.1.6)
WordPress Plugin WooCommerce Cross-Site Scripting (3.5.0)
Drupal Core 4.6.x Cross-Site Scripting (4.6.0 - 4.6.5)
Apache Tomcat Other Vulnerability (CVE-2023-45648)
PostgreSQL Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2005-0227)