peter bassill · operator
$ cve CVE-2023-4548 JSON

CVE-2023-4548 EXPLOIT

6.3
MEDIUM · CVSS 3.1 · EPSS 32.2% (pctl 98)

Patch early

A public exploit exists.

Description

A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3. The impacted element is an unknown function of the file /search of the component GET Parameter Handler. Such manipulation of the argument filter[brandid] leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. Upgrading to version 1.9.1.4 is sufficient to resolve this issue. You should upgrade the affected component.

Scoring

CVSS6.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS32.23% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-74
On CISA KEVno
Public exploityes
Published2023-08-26
Last modified2026-09-22

Affected (1)

VendorProduct
spa-cartecommerce cms

Public exploits

SourceTitleDate
exploit-dbSPA-Cart eCommerce CMS 1.9.0.3 - SQL Injection2023-09-08

References

→ the Explorer  ·  watch your stack  ·  NVD