OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in the blog's editor is not properly sanitized or escaped before being rendered. This allows attackers to inject malicious JavaScript code
References
| Link | Resource |
|---|---|
| https://packetstorm.news/files/id/202886 | Third Party Advisory |
| https://www.opencart.com | Product |
Configurations
History
No history.
Information
Published : 2025-07-25 17:15
Updated : 2025-08-07 14:19
NVD link : CVE-2025-45892
Mitre link : CVE-2025-45892
CVE.ORG link : CVE-2025-45892
JSON object : View
Products Affected
opencart
- opencart
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
