CVE-2021-47923Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSESSID cookie. Attackers can set malicious OCSESSID cookie values that the server accepts and maintains, enabling session takeover and unauthorized access to user accounts.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-10: 2PoC Mentioned / Linked · 2026-05-10: 1Patch / Workaround · 2026-05-10: 1Technical Details · 2026-05-10: 205-10
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Entity@0x2ed3bb60
    Patch

    🚨 CRITICAL: CVE-2021-47923 in OpenCart 3.0.3.8. Session fixation via OCSESSID cookie injection. Attacker sets arbitrary session ID, server accepts, session hijack achieved. Patch immediately. https://0x2ed3bb60.xyz/threat/0599db3392afde3b

    Post summary

    A critical session‑fixation vulnerability in OpenCart 3.0.3.8 is announced with an immediate patch call.

    0003048
    7 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2021-47923 OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSESSID cookie. Attac… https://www.cve.org/CVERecord?id=CVE-2021-47923

    Post summary

    The post announces CVE-2021-47923, a session fixation flaw in OpenCart 3.0.3.8, which lets attackers hijack user sessions by injecting values into the OCSESSID cookie, but it offers no PoC, exploit, or patch information.

    0000084
    57.5K followersView on X

Explore more