vendor:
SPA-Cart eCommerce CMS
by:
CraCkEr
6.1
CVSS
MEDIUM
Reflected XSS
79, 74, 707
CWE
Product Name: SPA-Cart eCommerce CMS
Affected Version From: 1.9.0.3
Affected Version To: 1.9.0.3
Patch Exists: NO
Related CWE: CVE-2023-4547
CPE: a:spa-cart_ecommerce_cms:1.9.0.3
Platforms Tested: Windows 10 Pro
2023
SPA-Cart eCommerce CMS 1.9.0.3 – Reflected XSS
The attacker can send to victim a link containing a malicious URL in an email or instant message, which can perform a wide variety of actions, such as stealing the victim's session token or login credentials
Mitigation:
Implement input validation and output encoding to prevent XSS attacks