A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticated attacker to inject arbitrary web script or HTML via a crafted User-Agent header. The script is executed in an administrator's browser when they view the security log page, which could lead to session hijacking or other malicious actions.
References
Configurations
History
No history.
Information
Published : 2025-09-23 16:15
Updated : 2025-10-08 18:10
NVD link : CVE-2025-57407
Mitre link : CVE-2025-57407
CVE.ORG link : CVE-2025-57407
JSON object : View
Products Affected
gp247
- gp247
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
