CVE-2025-0974
CVSS 3.1 Score 5 of 10 (medium)
Details
Published Feb 3, 2025
CWE ID 502
CWE ID 20
Summary
CVE-2025-0974 is a critical vulnerability affecting MaxD Lightning Module 4.43 on OpenCart. The issue lies in an unknown processing function where manipulation of the li_op/md argument can lead to deserialization. This vulnerability can be exploited remotely, making it a significant security risk. The complexity of an attack is relatively high, and the exploitation is considered difficult. However, the exploit for this vulnerability has been publicly disclosed, increasing the potential for successful attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share