Post by adibranch » Mon Jul 14, 2025 11:44 pm

Hi, i've got a couple of openbugbounty reports outlining an XSS issue on the search function. I'm running 3.0.2.0

Parameter: index.php?route=product/search&search=

Is this something inherent in the opencart 3.0.2.0 release and later patched, or is it possibly coming from the theme i'm using?

New member

Posts

Joined
Tue Jul 11, 2017 12:48 am

Post by OSWorX » Tue Jul 15, 2025 12:48 am

As far as I know, OpenCart has no problems with such.
Therefore it could come from your theme if they have their own function for that.

Maybe you share the used theme here (which should always be provided when you read this: Forum Rules ).

Full Stack Web Developer :: Dedicated OpenCart Development & Support DACH Region
Contact for Custom Work / Fast Support.


User avatar
Administrator

Posts

Joined
Mon Jan 11, 2010 10:52 pm
Location - Austria

Post by ADD Creative » Tue Jul 15, 2025 1:10 am

Were there any more details?

There is CVE-2025-1746 which mentions an XSS issue with product/search.
https://www.incibe.es/en/incibe-cert/no ... s-opencart

There isn't much in the way of details and It says it's fixed 4.1.0.0 and above, but no mention if it affects 3.0.x.

www.add-creative.co.uk


Guru Member

Posts

Joined
Sat Jan 14, 2012 1:02 am
Location - United Kingdom

Post by adibranch » Tue Jul 15, 2025 6:44 pm

OSWorX wrote:
Tue Jul 15, 2025 12:48 am
As far as I know, OpenCart has no problems with such.
Therefore it could come from your theme if they have their own function for that.

Maybe you share the used theme here (which should always be provided when you read this: Forum Rules ).
The theme is Journal 2.

New member

Posts

Joined
Tue Jul 11, 2017 12:48 am

Post by adibranch » Tue Jul 15, 2025 6:53 pm

ADD Creative wrote:
Tue Jul 15, 2025 1:10 am
Were there any more details?

There is CVE-2025-1746 which mentions an XSS issue with product/search.
https://www.incibe.es/en/incibe-cert/no ... s-opencart

There isn't much in the way of details and It says it's fixed 4.1.0.0 and above, but no mention if it affects 3.0.x.
Yes, details as below. I've omitted the site name for obvious reasons :)

Attachments

???
Screenshot 2025-07-15 115013.jpg

New member

Posts

Joined
Tue Jul 11, 2017 12:48 am

Post by JNeuhoff » Tue Jul 15, 2025 8:22 pm

I am certain it's resolved in OpenCart 3.0.4.0 or later. Besides, you are using the Journal2 framework, which isn't a proper standard OpenCart theme, also it uses its own search function.

Export/Import Tool * SpamBot Buster * Unused Images Manager * Instant Option Price Calculator * Number Option * Google Tag Manager * Survey Plus * OpenTwig


User avatar
Guru Member

Posts

Joined
Wed Dec 05, 2007 3:38 am


Post by ADD Creative » Tue Jul 15, 2025 9:47 pm

adibranch wrote:
Tue Jul 15, 2025 6:53 pm
Yes, details as below. I've omitted the site name for obvious reasons :)
I wasn't able to recreate the issue on 3.0.2.0 or 3.0.4.1. That suggests the issue is with your theme or an extension you are using.

www.add-creative.co.uk


Guru Member

Posts

Joined
Sat Jan 14, 2012 1:02 am
Location - United Kingdom
Who is online

Users browsing this forum: Amazon [Bot], Bing [Bot], Google [Bot], Majestic-12 [Bot], paola_84 and 20 guests