vendor:
SPA-Cart eCommerce CMS
by:
CraCkEr
9.8
CVSS
CRITICAL
SQL Injection
89 / 74 / 707
CWE
Product Name: SPA-Cart eCommerce CMS
Affected Version From: 1.9.0.3
Affected Version To: 1.9.0.3
Patch Exists: NO
Related CWE: CVE-2023-4548
CPE: a:spa-cart:ecommerce_cms:1.9.0.3
Platforms Tested: Windows 10 Pro
2023
SPA-Cart eCommerce CMS 1.9.0.3 – SQL Injection
SQL injection attacks can allow unauthorized access to sensitive data, modification of data and crash the application or make it unavailable, leading to lost revenue and damage to a company's reputation.
Mitigation:
Implement proper input validation and sanitization to prevent SQL injection attacks. Use prepared statements or parameterized queries to prevent dynamic SQL queries.