CVE-2025-0579: Shiprocket Module REST API Module restapi sql injection
A vulnerability was found in Shiprocket Module 3/4 on OpenCart. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /index.php?route=extension/shiprocket/module/restapi of the component REST API Module. The manipulation of the argument x-username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0579?
CVE-2025-0579 has been declared as a critical vulnerability.
What components are affected by CVE-2025-0579?
CVE-2025-0579 affects the Shiprocket Module and the OpenCart REST API Module.
How can I fix CVE-2025-0579?
To fix CVE-2025-0579, update the Shiprocket Module and the OpenCart REST API Module to their latest secure versions.
What is the exploitation method of CVE-2025-0579?
CVE-2025-0579 involves the manipulation of the arguments within the file /index.php?route=extension/shiprocket/module/restapi.
Is there a known proof of concept for CVE-2025-0579?
As of now, there is no public proof of concept available for CVE-2025-0579.