← back
CVE-2023-4547

SPA-Cart eCommerce CMS search cross site scripting

CVSS 3.5 LOWEPSS 48.5%CWE-79
Vexday Risk Score
55Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 3.5EPSS 48.5%KEV nãoPoC públicaNuclei simMetasploit Patch
Lifecycle
26 Aug 2023Published on NVD
04 Sep 2023Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
A vulnerability was found in SPA-Cart eCommerce CMS 1.9.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /search. The manipulation of the argument filter[brandid]/filter[price] leads to cross site scripting. The attack may be launched remotely. VDB-238058 is the identifier assigned to this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Affected products
SPA-Cart · eCommerce CMS
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →