Product Referenceproduct
https://codecanyon.net/item/amazcart-laravel-ecommerce-system-cms/34962179 CVE-2023-54349
MEDIUM
AmazCart CMS 3.4 Reflected Cross-Site Scripting via Search
Record summary
CVE-2023-54349 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.
Description
AmazCart CMS 3.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search functionality. Attackers can enter script tags in the search box to execute arbitrary JavaScript that fires when search history is viewed or results are displayed.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 5, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
AmazCart CMSBrowse Spondonit / AmazCart CMS | CVE List | 3.4 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBAmazCart CMS 3.4 - Cross-Site-Scripting (XSS)ExploitDB exploitby Sajibe KantiNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-54349 Official Product Homepageproduct
https://spondonit.com/ ExploitDB-51219exploit
https://www.exploit-db.com/exploits/51219 VulnCheck Advisory: AmazCart CMS 3.4 Reflected Cross-Site Scripting via SearchThird-party advisory
https://www.vulncheck.com/advisories/amazcart-cms-reflected-cross-site-scripting-via-search