CVE-2025-15116
Performing a manipulation results in race condition.
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
A security flaw has been discovered in OpenCart up to 4.1.0.3. Affected by this issue is some unknown functionality of the component Single-Use Coupon Handler. Performing a manipulation results in race condition. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitation is known to be difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 4.0
- 2.9 LOWCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- opencart/opencart
- Source
- cna@vuldb.com
References
- https://gist.github.com/KhanMarshaI/a55f125a55de1c0d4f41e66236027e01Exploit, Third Party Advisory
- https://gist.github.com/KhanMarshaI/a55f125a55de1c0d4f41e66236027e01#steps-to-reproduceExploit, Third Party Advisory
- https://vuldb.com/?ctiid.338494Permissions Required, VDB Entry
- https://vuldb.com/?id.338494Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.711745Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.