CVE-2018-25336: Joomla jCart for OpenCart 2.3.0.2 Cross-Site Request Forgery
Joomla jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information without authentication. Attackers can craft malicious HTML forms targeting endpoints , and to change user credentials, passwords, and affiliate account details when victims visit the attacker-controlled page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25336?
CVE-2018-25336 is considered a medium severity vulnerability due to its nature as a cross-site request forgery flaw.
How do I fix CVE-2018-25336?
To mitigate CVE-2018-25336, upgrade Joomla jCart for OpenCart to a version that addresses this vulnerability.
What type of vulnerability is CVE-2018-25336?
CVE-2018-25336 is a cross-site request forgery (CSRF) vulnerability.
Who is affected by CVE-2018-25336?
CVE-2018-25336 affects users of Joomla jCart for OpenCart version 2.3.0.2.
What can attackers do with CVE-2018-25336?
Attackers can exploit CVE-2018-25336 to modify user account information without authentication.