HTML Injection Vulnerability in OpenCart by OpenCart
CVE-2025-1748
4.7MEDIUM
What is CVE-2025-1748?
The vulnerability allows attackers to exploit HTML injection weaknesses in OpenCart versions prior to 4.1.0. By crafting a malicious URL that modifies the parameter name in the /account/register endpoint, an attacker can manipulate the HTML displayed in a victim's browser. This may lead to unauthorized access or data manipulation, emphasizing the importance of upgrading to secure versions.
Affected Version(s)
OpenCart 0 < 4.1.0