CVE-2025-1746

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Feb 28, 2025
CWE ID 79

Summary

CVE-2025-1746 is a Cross-Site Scripting (XSS) vulnerability affecting OpenCart versions below 4.1.0. An attacker can exploit this issue by crafting a malicious URL and using the search function in the /product/search endpoint. If a user visits the malicious URL, an attacker can inject and execute malicious JavaScript code in their browser. The potential consequences of this vulnerability include data theft, such as session cookies, and the ability to perform actions on behalf of the user.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share