Record summary

CVE-2023-54349 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.

Description

AmazCart CMS 3.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search functionality. Attackers can enter script tags in the search box to execute arbitrary JavaScript that fires when search history is viewed or results are displayed.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 5, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List3.4affected

Proofs of concept

1

Catalogued exploits

ExploitDBAmazCart CMS 3.4 - Cross-Site-Scripting (XSS)ExploitDB exploitby Sajibe KantiNot analyzed1 file
ExploitDB

PoC details

References

5