MEDIUM
ZenCart CKEditor cross site scripting
Published Aug 18, 2025
4.8
MEDIUMCVSS 4.0
EPSS 0.27%
Description
A vulnerability was detected in ZenCart 2.1.0. Affected by this vulnerability is an unknown functionality of the component CKEditor. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor declares this as "intended behavior, allowed for authorized administrators".
Affected products
- Vendor n/a Product ZenCart Defaultn/a
- Version 2.1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | ZenCart | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://gist.github.com/0xHamy/b2674eeffd1f73af96d29f152c47bcbd exploit
- https://hkohi.ca/vulnerability/28 exploitrelated
- https://vuldb.com/?ctiid.320425 signaturepermissions-required
- https://vuldb.com/?id.320425 vdb-entry
- https://vuldb.com/?submit.628298 exploitthird-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://gist.github.com/0xHamy/b2674eeffd1f73af96d29f152c47bcbd | exploit | |
| https://hkohi.ca/vulnerability/28 | exploitrelated | |
| https://vuldb.com/?ctiid.320425 | signaturepermissions-required | |
| https://vuldb.com/?id.320425 | vdb-entry | |
| https://vuldb.com/?submit.628298 | exploitthird-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 18, 2025
Updated Aug 18, 2025
Reserved Aug 17, 2025
Link CVE-2025-9103
CISA Vulnrichment
Updated Aug 18, 2025