CVE-2024-58304

⚪ Do wiadomości

W SPA-CART CMS występuje podatność na XSS, umożliwiająca atakującym wstrzykiwanie skryptów.

CVSS
6.1
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

SPA-CART CMS before 2.0.0 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through the 'descr' parameter in the product edit form to execute arbitrary code in administrative users' browsers.

xss Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2025-12-11 22:15:51 UTC
Ostatnia modyfikacja (NVD)2026-09-28 20:17:06 UTC
Referencje