PT-2025-39177 · S-Cart · S-Cart

Published

2025-09-23

·

Updated

2025-09-24

·

CVE-2025-57407

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions S-Cart versions prior to 10.0.4
Description A stored cross-site scripting (XSS) issue exists in the Admin Log Viewer component. A remote, authenticated attacker can inject arbitrary web script or HTML through a manipulated User-Agent header. When an administrator views the security log page, the injected script is executed in their browser, potentially leading to session hijacking or other malicious activities.
Recommendations Update S-Cart to version 10.0.4 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-57407
GHSA-46V4-5MC8-Q2CF

Affected Products

S-Cart