CVE-2024-21517
medium
CVSS v3
6.1
CVSS v2
—
VIR risk
6.1
Description
Cross site scripting in opencart
Predictions
Exploit likelihood
71%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: report@snyk.io — https://security.snyk.io/vuln/SNYK-PHP-OPENCARTOPENCART-7266577
Vendor advisory: report@snyk.io — https://github.com/opencart/opencart/commit/0fd1ee4b6c94366bf3e5d3831a8336f3275d1860
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | opencart/opencart | >=4.0.0.0 | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| opencart | opencart | {"startIncluding":"4.0.0.0"} | |
References
CWEs
CWE-79
Verify integrity in audit chain (admin only). AS-IS.