CVE-2025-1748: HTML injection vulnerability in OpenCart
HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/register.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1748?
CVE-2025-1748 is considered a significant security vulnerability due to its potential to allow HTML injection in vulnerable OpenCart versions.
How do I fix CVE-2025-1748?
To fix CVE-2025-1748, upgrade OpenCart to version 4.1.0 or later to ensure protection against HTML injection vulnerabilities.
What are the risks associated with CVE-2025-1748?
The risks associated with CVE-2025-1748 include unauthorized modifications to the HTML of the victim’s browser, which can lead to phishing or malware attacks.
Which versions of OpenCart are affected by CVE-2025-1748?
CVE-2025-1748 affects all OpenCart versions prior to 4.1.0.
How can attackers exploit CVE-2025-1748?
Attackers can exploit CVE-2025-1748 by sending a malicious URL that modifies the parameter name in /account/register, allowing them to inject malicious HTML into the victim's browser.