Логотип exploitDog
bind:CVE-2024-58304
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-58304

Количество 2

Количество 2

nvd логотип

CVE-2024-58304

около 2 месяцев назад

SPA-CART CMS 1.9.0.3 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through the 'descr' parameter in the product edit form to execute arbitrary code in administrative users' browsers.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-85x8-963x-rfj7

около 2 месяцев назад

SPA-CART CMS 1.9.0.3 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through the 'descr' parameter in the product edit form to execute arbitrary code in administrative users' browsers.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-58304

SPA-CART CMS 1.9.0.3 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through the 'descr' parameter in the product edit form to execute arbitrary code in administrative users' browsers.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-85x8-963x-rfj7

SPA-CART CMS 1.9.0.3 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through the 'descr' parameter in the product edit form to execute arbitrary code in administrative users' browsers.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу