CVE-2025-1746: Cross-Site Scripting vulnerability in OpenCart
Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the search in the /product/search endpoint. This vulnerability could be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1746?
CVE-2025-1746 is considered a medium severity Cross-Site Scripting vulnerability.
How do I fix CVE-2025-1746?
To fix CVE-2025-1746, upgrade your OpenCart installation to version 4.1.0 or later.
What versions of OpenCart are affected by CVE-2025-1746?
CVE-2025-1746 affects all OpenCart versions prior to 4.1.0.
What data can be compromised due to CVE-2025-1746?
CVE-2025-1746 can allow an attacker to execute arbitrary JavaScript code in the victim's browser.
How can an attacker exploit CVE-2025-1746?
An attacker can exploit CVE-2025-1746 by sending a malicious URL through the /product/search endpoint.