Miggo Logo

CVE-2025-57407: GP247 and S-Cart have a stored cross-site scripting (XSS) vulnerability

N/A

CVSS Score

Basic Information

EPSS Score
-
Published
9/23/2025
Updated
9/23/2025
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
-
Package NameEcosystemVulnerable VersionsFirst Patched Version
s-cart/corecomposer<= 9.0.5
gp247/corecomposer< 1.1.241.1.24

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

* stor** *ross-sit* s*riptin* (XSS) vuln*r**ility in t** **min Lo* Vi*w*r o* S-**rt <=**.*.* *llows * r*mot* *ut**nti**t** *tt**k*r to inj**t *r*itr*ry w** s*ript or *TML vi* * *r**t** Us*r-***nt *****r. T** s*ript is *x**ut** in *n **ministr*tor's *

Reasoning

No *n*lysis *v*il**l*