CVE-2025-1747: HTML injection vulnerability in OpenCart
Published Feb 28, 2025
·Updated
HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/login.
Affected Software
2 affected components
OpenCart OpenCart<4.1.0
OpenCart OpenCart<4.1.0.0
Remediation
Information
The vulnerability has been fixed by the OpenCart team in version 4.1.0.
Event History
Feb 28, 2025
CVE Published
via MITRE·01:42 PM
Data Sourced
via MITRE·01:42 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-1747?
The severity of CVE-2025-1747 is considered medium, due to its potential to allow HTML injection attacks.
2
How do I fix CVE-2025-1747?
To fix CVE-2025-1747, upgrade OpenCart to version 4.1.0 or later to eliminate the HTML injection vulnerabilities.
3
Which versions of OpenCart are affected by CVE-2025-1747?
OpenCart versions prior to 4.1.0 are affected by CVE-2025-1747.
4
What can an attacker do with CVE-2025-1747?
An attacker can use CVE-2025-1747 to modify the HTML of the victim's browser by sending a malicious URL.
5
Is CVE-2025-1747 a widely exploited vulnerability?
As of now, there are no known widespread exploits for CVE-2025-1747, but it poses a risk if not addressed.