{"id":"CVE-2021-37823","aliases":["GHSA-236j-rfx5-wq38"],"url":"https://o3.security/vulnerability/CVE-2021-37823","summary":"OpenCart SQL injection vulnerability","details":"OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the background.","published":"2022-11-03T17:15:17.217Z","modified":"2026-07-09T01:31:33.569795Z","cvss":{"score":4.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.00761,"percentile":0.53647,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Packagist","name":"opencart/opencart","fixedVersion":null}],"fix":null,"references":[{"type":"EVIDENCE","url":"https://medium.com/%40nowczj/sql-injection-exists-in-the-background-of-opencart-d41b5c58e99e"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-37823"},{"type":"PACKAGE","url":"https://github.com/opencart/opencart"},{"type":"WEB","url":"https://medium.com/@nowczj/sql-injection-exists-in-the-background-of-opencart-d41b5c58e99e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T01:31:33.569795Z"}}