VYPR

Ecommerce CMS

by Spa Cart

CVEs (2)

  • CVE-2023-4548MedAug 26, 2023
    risk 0.46cvss 6.3epss 0.20

    A vulnerability classified as critical has been found in SPA-Cart eCommerce CMS 1.9.0.3. This affects an unknown part of the file /search of the component GET Parameter Handler. The manipulation of the argument filter[brandid] leads to sql injection. It is possible to initiate…

  • CVE-2023-4547LowAug 26, 2023
    risk 0.30cvss 3.5epss 0.49

    A vulnerability was found in SPA-Cart eCommerce CMS 1.9.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /search. The manipulation of the argument filter[brandid]/filter[price] leads to cross site scripting. The attack may…