CVE-2025-0841

HIGH

Aridius XYZ <20240927 - Deserialization

Title source: llm
STIX 2.1

Description

A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability affects the function loadMore of the component News. The manipulation leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.293998
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.293998
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.485445

Scores

CVSS v3 7.3
EPSS 0.0046
EPSS Percentile 36.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-502
Status published
Products (1)
Aridius/XYZ 20240927
Published Jan 29, 2025
Tracked Since Feb 18, 2026