Description
/upload/catalog/controller/account/password.php in OpenCart through 3.0.2.0 has CSRF via the index.php?route=account/password URI to change a user's password.
Remediation
References
Related Vulnerabilities
WordPress Plugin Wow Moodboard Lite Open Redirect (1.1.1.1)
Apache Tomcat Other Vulnerability (CVE-2003-0045)
WordPress Plugin Contact Form DB Cross-Site Scripting (2.10.29)
Jenkins Incorrect Authorization Vulnerability (CVE-2022-34175)
Joomla! Core 1.5.x Multiple SQL Injection Vulnerabilities (1.5.0 - 1.5.21)