CVE-2023-4547
LOW NUCLEISPA-Cart eCommerce CMS 1.9.0.3 - XSS
Title source: llmDescription
A vulnerability was found in SPA-Cart eCommerce CMS 1.9.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /search. The manipulation of the argument filter[brandid]/filter[price] leads to cross site scripting. The attack may be launched remotely. VDB-238058 is the identifier assigned to this vulnerability.
Exploits (1)
Nuclei Templates (1)
SPA-Cart eCommerce CMS 1.9.0.3 - Cross-Site Scripting
MEDIUMVERIFIEDby theamanrawat,SoSpiRo
References (3)
Scores
CVSS v3
3.5
EPSS
0.1040
EPSS Percentile
93.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
spa-cart/ecommerce_cms
1.9.0.3
Published
Aug 26, 2023
Tracked Since
Feb 18, 2026