SPA-CART CMS Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in SPA-CART CMS version 1.9.0.3. This issue resides in the product description parameter, allowing authenticated administrators to inject malicious scripts. By submitting JavaScript payloads through the 'descr' parameter in the product edit form, attackers can execute arbitrary code in the browsers of administrative users.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the product, potentially leading to session hijacking or other malicious actions.

Reproduction

To reproduce this vulnerability, an authenticated administrator can navigate to the product edit form for any product. Once there, injecting a script payload into the 'descr' parameter will trigger the cross-site scripting vulnerability when the product description is viewed.

Added: Dec 11, 2025, 10:29 PM
Updated: Dec 11, 2025, 10:29 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
1.7
exploitability
6.0
remediation
0.0
relevance
1.4
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.