OpenCart
cpe:2.3:a:opencart:opencart:*:*:*:*:*:*:*
- < 4.1.0
A vulnerability allowing HTML injection has been identified in OpenCart versions prior to 4.1.0. This issue could enable an attacker to alter the HTML displayed in the victim's browser by sending a malicious URL that modifies the parameter name in the '/account/voucher' endpoint.
Exploitation of this vulnerability could lead to unauthorized modification of the victim's browser HTML, potentially allowing for further attacks such as Cross-Site Scripting.
Users can upgrade to OpenCart version 4.1.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.