CVE-2025-1747
Last modified
CVE-2025-1747 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/login.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/login.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opencart | Opencart | < 4.1.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-1747?
How severe is CVE-2025-1747?
How do I fix CVE-2025-1747?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-1741A vulnerability classified as problematic was found in b1gMa…5.1
- CVE-2025-1742A vulnerability, which was classified as problematic, has be…6.1
- CVE-2025-1743A vulnerability, which was classified as critical, was found…6.9
- CVE-2025-1744Out-of-bounds Write vulnerability in radareorg radare2 allow…9.8
- CVE-2025-1745A vulnerability has been found in LinZhaoguan pb-cms 2.0 and…5.3
- CVE-2025-1746Cross-Site Scripting vulnerability in OpenCart versions prio…6.1
- CVE-2025-1748HTML injection vulnerabilities in OpenCart versions prior to…4.7
- CVE-2025-1749HTML injection vulnerabilities in OpenCart versions prior to…4.7
- CVE-2025-1750An SQL injection vulnerability exists in the delete function…9.8
- CVE-2025-1751A SQL Injection vulnerability has been found in Ciges 2.15.5…9.8
- CVE-2025-1752A Denial of Service (DoS) vulnerability has been identified …7.5
- CVE-2025-1753LLama-Index CLI version v0.12.20 contains an OS command inje…7.8
Are you affected by CVE-2025-1747?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
