A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticated attacker to inject arbitrary web script or HTML via a crafted User-Agent header. The script is executed in an administrator's browser when they view the security log page, which could lead to session hijacking or other malicious actions.
References
Configurations
History
08 Oct 2025, 18:10
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:gp247:gp247:*:*:*:*:*:*:*:* | |
References | () https://github.com/gp247net/core/releases/tag/1.1.24 - Release Notes | |
References | () https://github.com/s-cart/core/blob/7c9aa42761be5fd0131c61dbe2b5323beb96d5dd/src/Admin/Controllers/AdminLogController.php - Product | |
First Time |
Gp247 gp247
Gp247 |
24 Sep 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
23 Sep 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-23 16:15
Updated : 2025-10-08 18:10
NVD link : CVE-2025-57407
Mitre link : CVE-2025-57407
CVE.ORG link : CVE-2025-57407
JSON object : View
Products Affected
gp247
- gp247
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')