OpenCart
cpe:2.3:a:opencart:opencart:*:*:*:*:*:*:*
- <= 4.1.0.4
A stored cross-site scripting vulnerability has been identified in OpenCart version 4.1.0.4 and earlier. This issue arises from the improper sanitization of SVG files uploaded through the media manager, allowing attackers to inject malicious JavaScript that executes when the SVG is rendered in a blog post.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected blog post.
To reproduce this vulnerability, create a malicious SVG file that includes embedded JavaScript, such as a script tag with a JavaScript alert. Upload this SVG file via the media manager and insert it into a blog post. When the post is viewed, the JavaScript executes, demonstrating the cross-site scripting vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.