VYPR
Critical severity9.8NVD Advisory· Published Sep 12, 2023· Updated Jun 17, 2026

CVE-2023-40834

CVE-2023-40834

Description

OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack to the password parameter.

Affected products

3
  • Opencart/Opencart2 versions
    cpe:2.3:a:opencart:opencart:4.0.2.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:opencart:opencart:4.0.2.2:*:*:*:*:*:*:*
    • (no CPE)range: = 4.0.2.2
  • OpenCart CMS/OpenCart CMSdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.