PT-2025-4120 · Unknown+1 · Maxd Lightning Module+1

Mcdruid

·

Published

2025-02-03

·

Updated

2025-02-03

·

CVE-2025-0974

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions MaxD Lightning Module version 4.43 on OpenCart
Description A critical issue has been found in the MaxD Lightning Module on OpenCart, affecting some unknown processing. The manipulation of the argument li op/md leads to deserialization. The attack can be initiated remotely, with a rather high complexity of attack and difficult exploitation. The exploit has been disclosed to the public and may be used.
Recommendations For MaxD Lightning Module version 4.43 on OpenCart, consider disabling the deserialization of the li op/md argument as a temporary workaround until a patch is available. Restrict access to the module to minimize the risk of exploitation. Avoid using the li op/md argument in the affected processing until the issue is resolved.

Exploit

Fix

Deserialization of Untrusted Data

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-0974

Affected Products

Maxd Lightning Module
Opencart