{"id":"CVE-2025-57407","aliases":["GHSA-46v4-5mc8-q2cf"],"url":"https://o3.security/vulnerability/CVE-2025-57407","summary":"GP247 and S-Cart have a stored cross-site scripting (XSS) vulnerability","details":"A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticated attacker to inject arbitrary web script or HTML via a crafted User-Agent header. The script is executed in an administrator's browser when they view the security log page, which could lead to session hijacking or other malicious actions.","published":"2025-09-23T00:00:00Z","modified":"2026-08-12T03:51:12.578771801Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"s-cart/core","fixedVersion":null},{"ecosystem":"Packagist","name":"gp247/core","fixedVersion":"1.1.24"}],"fix":{"url":"https://github.com/gp247net/core/commit/e9848706b41d835ca3d668cb1554650403e86da1","label":"gp247net/core@e984870"},"references":[{"type":"WEB","url":"https://github.com/gp247net/core/releases/tag/1.1.24"},{"type":"WEB","url":"https://github.com/s-cart/core/blob/7c9aa42761be5fd0131c61dbe2b5323beb96d5dd/src/Admin/Controllers/AdminLogController.php"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57407.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-57407"},{"type":"WEB","url":"https://github.com/gp247net/core/commit/e9848706b41d835ca3d668cb1554650403e86da1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.578771801Z"}}