CVE-2025-0580

CVSS 3.1 Score 5.6 of 10 (medium)

Details

Published Jan 20, 2025
CWE ID 285
CWE ID 863

Summary

CVE-2025-0580 is a critical vulnerability identified in the Shiprocket Module 3 component of OpenCart's REST API Module. This issue lies within the /index.php?route=extension/module/rest_api&action=getOrders functionality, where manipulation of the argument contentHash results in incorrect authorization. This vulnerability can be exploited remotely, with a high degree of complexity and known difficulty. Despite early disclosure to the vendor, they have not responded or taken any action to address the issue, making it publicly accessible for potential attackers.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share