CVE-2025-1749: HTML injection vulnerability in OpenCart
HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/voucher.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1749?
CVE-2025-1749 is classified as a medium severity vulnerability due to its potential to allow HTML injection in affected OpenCart versions.
How do I fix CVE-2025-1749?
To fix CVE-2025-1749, update OpenCart to version 4.1.0 or later to mitigate the HTML injection vulnerabilities.
What versions of OpenCart are affected by CVE-2025-1749?
CVE-2025-1749 affects OpenCart versions prior to 4.1.0.
What types of attacks can CVE-2025-1749 facilitate?
CVE-2025-1749 can facilitate attacks that modify the HTML content displayed in the victim's browser via malicious URLs.
Are there any known exploits for CVE-2025-1749?
As of now, there have been no publicly reported exploits specifically targeting CVE-2025-1749.