CVE-2024-58304
⚪ Do wiadomości
W SPA-CART CMS występuje podatność na XSS, umożliwiająca atakującym wstrzykiwanie skryptów.
CVSS
6.1
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)
SPA-CART CMS before 2.0.0 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through the 'descr' parameter in the product edit form to execute arbitrary code in administrative users' browsers.
xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2025-12-11 22:15:51 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-28 20:17:06 UTC |