Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-30918 | A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticated attacker to inject arbitrary web script or HTML via a crafted User-Agent header. The script is executed in an administrator's browser when they view the security log page, which could lead to session hijacking or other malicious actions. |
Github GHSA |
GHSA-46v4-5mc8-q2cf | GP247 and S-Cart have a stored cross-site scripting (XSS) vulnerability |
Wed, 08 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gp247
Gp247 gp247 |
|
| CPEs | cpe:2.3:a:gp247:gp247:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gp247
Gp247 gp247 |
Wed, 24 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Tue, 23 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticated attacker to inject arbitrary web script or HTML via a crafted User-Agent header. The script is executed in an administrator's browser when they view the security log page, which could lead to session hijacking or other malicious actions. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-24T14:19:10.375Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-57407
Updated: 2025-09-24T14:18:54.775Z
Status : Analyzed
Published: 2025-09-23T16:15:32.567
Modified: 2026-06-17T09:43:04.900
Link: CVE-2025-57407
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA