Zero-Day Advisory
Fortinet Discovers OpenCart Cross-Site Scripting Vulnerability
Summary
Fortinet's FortiGuard Labs has discovered a Cross-Site Scripting vulnerability in OpenCart.
OpenCart is an open source PHP-based online e-commerce solution. OpenCart powers over 471669 eCommerce Entrepreneurs all over the world.
A Cross-Site Scripting vulnerability has been discovered in OpenCart. The vulnerability is caused due to insufficiently sanitizing search values. It allows remote attackers to launch Cross-Site Scripting attack against OpenCart users.
Solutions
FortiGuard Labs released the following FortiGate IPS signature which covers this specific vulnerability:OpenCart.Search.Header.Injection.XSS
Released Sep 14, 2017
Users should apply the solution provided by OpenCart.
Timeline
Fortinet reported the vulnerability to OpenCart on September 1, 2017.
OpenCart confirmed the vulnerability on September 5, 2017.