CVE-2025-57407: GP247

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticated attacker to inject arbitrary web script or HTML via a crafted User-Agent header. The script is executed in an administrator's browser when they view the security log page, which could lead to session hijacking or other malicious actions.

Affected products

  • GP247 GP247: before 1.1.24 (fixed in 1.1.24)

Published 2025-09-23. Last modified 2026-06-17.