PT-2025-30911 · Opencart · Opencart 4.1.0.4

Published

2025-07-25

·

Updated

2025-08-07

·

CVE-2025-45893

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenCart version 4.1.0.4
Description OpenCart version 4.1.0.4 is susceptible to a Stored Cross-Site Scripting (XSS) attack through the upload of SVG files used in blog posts. The issue occurs because SVG files uploaded via the media manager are not adequately sanitized, allowing attackers to embed malicious JavaScript code within them.
Recommendations Ensure proper sanitization of SVG files uploaded through the media manager.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-OPENCART-2025-45893
CVE-2025-45893

Affected Products

Opencart 4.1.0.4