CVE-2025-1749

Published Feb 28, 2025

Last updated 14 days ago

Overview

Description
HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/voucher.
Source
cve-coordination@incibe.es
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
4.7
Impact score
1.4
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Severity
MEDIUM

Weaknesses

cve-coordination@incibe.es
CWE-79

Social media

Hype score
Not currently trending

Configurations