---
id: CVE-2021-47946
title: >-
  OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the
  /account/edit endpoint that allows unauthenticated attackers to modify victim
  account details by tricking users into visiting malicious pages
summary: >-
  OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the
  /account/edit endpoint that allows unauthenticated attackers to modify victim
  account details by tricking users into visiting malicious pages. Attackers can
  craf…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-352
published: '2026-05-10'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-47946'
references:
  - url: 'https://www.exploit-db.com/exploits/49407'
    label: disclosure@vulncheck.com
  - url: 'https://www.opencart.com'
    label: disclosure@vulncheck.com
  - url: 'https://www.opencart.com/index.php?route=cms/download'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/opencart-account-takeover-via-cross-site-request-forgery
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00151
epssPercentile: 0.03674
ingestedAt: '2026-10-06T22:23:15.922Z'
---

## Overview

OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthenticated attackers to modify victim account details by tricking users into visiting malicious pages. Attackers can craft CSRF payloads that change victim email addresses and account information, then use password reset functionality to gain unauthorized access to compromised accounts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
