CVE-2024-58304
- EPSS 0.03%
- Veröffentlicht 11.12.2025 21:40:42
- Zuletzt bearbeitet 12.12.2025 21:15:50
SPA-CART CMS 1.9.0.3 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through the 'descr' paramete...
CVE-2024-6129
- EPSS 0.24%
- Veröffentlicht 18.06.2024 21:15:57
- Zuletzt bearbeitet 21.11.2024 09:49:01
A vulnerability, which was classified as problematic, was found in spa-cartcms 1.9.0.6. Affected is an unknown function of the file /login of the component Username Handler. The manipulation of the argument email leads to observable behavioral discre...
CVE-2024-6128
- EPSS 0.14%
- Veröffentlicht 18.06.2024 21:15:56
- Zuletzt bearbeitet 21.11.2024 09:49:01
A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unknown processing of the file /checkout of the component Checkout Page. The manipulation of the argument quantity with the input -10...