Advisory Information: Title: OpenCart CSRF Vulnerability Advisory URL: http://blog.visionsource.org/2010/01/28/opencart-csrf-vulnerability/ Date published: 2010-01-28 Vendors contacted: OpenCart Security Risk: High Vulnerability Description: OpenCart is vulnerable to CSRF attacks using the POST method. It is possible to craft a malicious page that will create an administrator user when the victim, who is logged into OpenCart, visits the malicious page. Proofs of Concept:
Results: (this frame can be hidden so the user never knows the attack was performed)