← Back to CVE List

CVE-2025-1746

Published: 2025-02-28T14:15Z
Last Modified: 2025-02-28T14:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the search in the /product/search endpoint. This vulnerability could be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt