OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in the blog's editor is not properly sanitized or escaped before being rendered. This allows attackers to inject malicious JavaScript code
References
Link | Resource |
---|---|
https://packetstorm.news/files/id/202886 | Third Party Advisory |
https://www.opencart.com | Product |
Configurations
History
07 Aug 2025, 14:19
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:opencart:opencart:*:*:*:*:*:*:*:* |
07 Aug 2025, 01:31
Type | Values Removed | Values Added |
---|---|---|
References | () https://packetstorm.news/files/id/202886 - Third Party Advisory | |
References | () https://www.opencart.com - Product | |
First Time |
Opencart
Opencart opencart |
|
CPE | cpe:2.3:a:opencart:opencart:4.1.0.4:*:*:*:*:*:*:* |
29 Jul 2025, 14:14
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
25 Jul 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
25 Jul 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-25 17:15
Updated : 2025-08-07 14:19
NVD link : CVE-2025-45892
Mitre link : CVE-2025-45892
CVE.ORG link : CVE-2025-45892
JSON object : View
Products Affected
opencart
- opencart
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')