在 OpenCart 4.1.0.3/4.1.0.4 中发现了一个漏洞。该漏洞影响了组件“Autocomplete Workflow”中文件 的一个未知功能。通过操纵 参数可触发跨站脚本(XSS)攻击。该攻击可远程发起。此漏洞的利用方式已公开披露,可能被实际利用。厂商此前已被通知此事,但未以任何方式做出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | OpenCart | 4.1.0.3 |
cpe:2.3:a:opencart:opencart:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84430 | 6.3 MEDIUM | gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes |
| CVE-2026-84437 | 3.5 LOW | OpenCart Autocomplete Workflow address.php cross site scripting |
No comments yet