CVE-2025-0974 Details
Description
A vulnerability was determined in MaxD Lightning Module 4.43/4.44 on OpenCart. This issue affects some unknown processing. Executing a manipulation of the argument li_op/md can lead to deserialization. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 4.45 is capable of addressing this issue. Upgrading the affected component is advised.
A critical vulnerability has been identified in the MaxD Lightning Module version 4.43 for OpenCart. This issue arises from the deserialization of untrusted data, specifically through the manipulation of the 'li_op' and 'md' parameters. The vulnerability allows for PHP Object Injection, which could be exploited using existing gadget chains in OpenCart versions 3 and 4. The exploitation of this vulnerability is remote but considered difficult.
The vulnerability could be mitigated by modifying the unserialize function to include the 'allowed_classes' option, disabling object injection. A more effective approach would be to replace serialization with JSON encoding and decoding.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 3, 2025CISA-ADP
Assessed Feb 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MaxD Lightning Module | All versions |
CPE
Remediation
| |
| OpenCart | 4.43 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 19, 2026 | CVE Modified | [email protected] |
| Feb 3, 2025 | New CVE Received | [email protected] |
Volerion