OpenCart Cross-Site Request Forgery Vulnerability Allowing Account Takeover

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in OpenCart version 3.0.36, specifically within the '/account/edit' endpoint. This vulnerability allows unauthenticated attackers to manipulate victim account details by deceiving users into visiting malicious websites. Exploitation involves crafting CSRF payloads that alter email addresses and other account information, which can then be leveraged to gain unauthorized access to the affected accounts via the password reset functionality.

Impact

Exploitation of this vulnerability can lead to unauthorized modification of user account details and account takeover.

Reproduction

To reproduce this vulnerability, an attacker must first create an account and log in. After intercepting a request to the '/account/edit' endpoint using a tool like Burp Suite, the attacker can modify the email address and save the request as an HTML file. Sending this file to the victim, who opens it, will trigger the CSRF attack by changing the account details. The attacker can then use the password reset feature to access the compromised account.

Added: May 10, 2026, 1:32 PM
Updated: May 10, 2026, 1:32 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
0.6
exploitability
7.7
remediation
0.0
relevance
7.9
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.