CVE-2025-9103 Information
Aug 19, 2025
cve
Description
A vulnerability was detected in ZenCart 2.1.0. Affected by this vulnerability is an unknown functionality of the component CKEditor. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor declares this as \intended behavior allowed for authorized administrators.
Reference
https://hkohi.ca/vulnerability/28 https://vuldb.com/?ctiid.320425 https://vuldb.com/?id.320425 https://gist.github.com/0xHamy/b2674eeffd1f73af96d29f152c47bcbd https://vuldb.com/?submit.628298 https://hkohi.ca/vulnerability/28 https://vuldb.com/?submit.628298
Related CNNVD
CNNVD-202508-1999 (Published: 2025-08-18)
Share on: