CVE-2025-0580
CVSS 3.1 Score 5.6 of 10 (medium)
Details
Summary
CVE-2025-0580 is a critical vulnerability identified in the Shiprocket Module 3 component of OpenCart's REST API Module. This issue lies within the /index.php?route=extension/module/rest_api&action=getOrders functionality, where manipulation of the argument contentHash results in incorrect authorization. This vulnerability can be exploited remotely, with a high degree of complexity and known difficulty. Despite early disclosure to the vendor, they have not responded or taken any action to address the issue, making it publicly accessible for potential attackers.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.