CVE-2025-45893: XSS
OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via SVG file uploads used in blog posts. The vulnerability arises because SVG files uploaded through the media manager are not properly sanitized. Attackers can craft a malicious SVG file containing embedded JavaScript
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-45893?
CVE-2025-45893 is classified as a medium severity vulnerability due to its potential for exploitation via stored XSS attacks.
How do I fix CVE-2025-45893?
To fix CVE-2025-45893, ensure that SVG file uploads are properly sanitized within OpenCart version 4.1.0.4.
What types of attacks can exploit CVE-2025-45893?
CVE-2025-45893 can be exploited through stored Cross-Site Scripting (XSS) attacks that leverage malicious SVG file uploads.
Which versions of OpenCart are affected by CVE-2025-45893?
CVE-2025-45893 affects OpenCart version 4.1.0.4 and potentially earlier versions if they do not patch this vulnerability.
Can CVE-2025-45893 be exploited by unauthenticated users?
Yes, CVE-2025-45893 can be exploited by unauthenticated users if they gain access to upload a malicious SVG file.