Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-85x8-963x-rfj7

Опубликовано: 12 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 7.5

Описание

SPA-CART CMS 1.9.0.3 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through the 'descr' parameter in the product edit form to execute arbitrary code in administrative users' browsers.

SPA-CART CMS 1.9.0.3 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through the 'descr' parameter in the product edit form to execute arbitrary code in administrative users' browsers.

EPSS

Процентиль: 23%
0.00076
Низкий

5.3 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

SPA-CART CMS 1.9.0.3 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through the 'descr' parameter in the product edit form to execute arbitrary code in administrative users' browsers.

EPSS

Процентиль: 23%
0.00076
Низкий

5.3 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-79