VYPR

Ecommerce CMS

by Spa Cart

CVEs (2)

  • CVE-2023-4548MedAug 26, 2023
    risk 0.46cvss 6.3epss 0.32

    A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3. The impacted element is an unknown function of the file /search of the component GET Parameter Handler. Such manipulation of the argument filter[brandid] leads to sql injection. The attack may be performed from…

  • CVE-2023-4547LowAug 26, 2023
    risk 0.31cvss 3.5epss 0.60

    A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3. The affected element is an unknown function of the file /search. This manipulation of the argument filter[brandid]/filter[price] causes cross site scripting. The attack is possible to be carried out remotely. The exploit…