← volver
CVE-2023-4547mediumCWE-79CWE-94

SPA-Cart eCommerce CMS search cross site scripting

60Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendcvss 5.1epss 60%
de la publicación al arma9 días
Publicada en NVD26 ago
1ª PoC+9d
probabilidad de explotación
60%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
2 exploit(s) público(s)
A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3. The affected element is an unknown function of the file /search. This manipulation of the argument filter[brandid]/filter[price] causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version 1.9.1.4 is sufficient to fix this issue. It is advisable to upgrade the affected component.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Productos afectados
SPA-Cart · eCommerce CMS
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.