CVE-2025-0841: Aridius XYZ News loadMore deserialization
A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability affects the function loadMore of the component News. The manipulation leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0841?
CVE-2025-0841 is classified as critical due to its potential impact on the affected systems.
How do I fix CVE-2025-0841?
To fix CVE-2025-0841, you should update Aridius OpenCart to a version beyond 20240927.
What are the consequences of exploiting CVE-2025-0841?
Exploiting CVE-2025-0841 can lead to remote deserialization attacks that compromise the application.
Which versions of OpenCart are affected by CVE-2025-0841?
CVE-2025-0841 affects all versions of Aridius OpenCart up to and including 20240927.
Can CVE-2025-0841 be exploited remotely?
Yes, CVE-2025-0841 can be exploited remotely without the need for physical access to the system.