CVE-2025-0214
CVSS 3.1 Score 4.1 of 10 (medium)
Details
Summary
CVE-2025-0214 is a recently identified vulnerability in the TMD Custom Header Menu 4.0.0.1 component of OpenCart. The issue, which is considered problematic, relates to an unsecured processing step in the /admin/index.php file. An attacker can exploit this vulnerability by manipulating the headermenu_id argument, which leads to SQL injection. The attack can be launched remotely, but the complexity is relatively high, making it difficult to execute. The exploit has been disclosed to the public, increasing the risk of potential attacks. To mitigate this threat, it is strongly advised to upgrade the affected component as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Custom Header Menu