Home

Description

A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticated attacker to inject arbitrary web script or HTML via a crafted User-Agent header. The script is executed in an administrator's browser when they view the security log page, which could lead to session hijacking or other malicious actions.

PUBLISHED Reserved 2025-08-17 | Published 2025-09-23 | Updated 2025-09-24 | Assigner mitre

References

github.com/...d/src/Admin/Controllers/AdminLogController.php

github.com/gp247net/core/releases/tag/1.1.24

cve.org (CVE-2025-57407)

nvd.nist.gov (CVE-2025-57407)

Download JSON