OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via SVG file uploads used in blog posts. The vulnerability arises because SVG files uploaded through the media manager are not properly sanitized. Attackers can craft a malicious SVG file containing embedded JavaScript
{
"cpes": [
"cpe:2.3:a:opencart:opencart:*:*:*:*:*:*:*:*"
],
"severity": "Medium"
}