CVE-2025-0214

CVSS 3.1 Score 4.1 of 10 (medium)

Details

Published Jan 4, 2025
CWE ID 74
CWE ID 89

Summary

CVE-2025-0214 is a recently identified vulnerability in the TMD Custom Header Menu 4.0.0.1 component of OpenCart. The issue, which is considered problematic, relates to an unsecured processing step in the /admin/index.php file. An attacker can exploit this vulnerability by manipulating the headermenu_id argument, which leads to SQL injection. The attack can be launched remotely, but the complexity is relatively high, making it difficult to execute. The exploit has been disclosed to the public, increasing the risk of potential attacks. To mitigate this threat, it is strongly advised to upgrade the affected component as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share