CVE-2024-21515
medium
CVSS v3
4.7
CVSS v2
—
VIR risk
4.7
Description
Cross site scripting in opencart
Predictions
Exploit likelihood
57%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: report@snyk.io — https://security.snyk.io/vuln/SNYK-PHP-OPENCARTOPENCART-7266573
Vendor advisory: report@snyk.io — https://github.com/opencart/opencart/commit/c546199e8f100c1f3797a7a9d3cf4db1887399a2
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | opencart/opencart | >=4.0.0.0 | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| opencart | opencart | {"startIncluding":"4.0.0.0"} | |
References
CWEs
CWE-79
Verify integrity in audit chain (admin only). AS-IS.