CVE-2023-4547
Executive Summary
SPA‑Cart eCommerce CMS 1.9.0.3 is vulnerable to a remote cross‑site scripting (XSS) flaw triggered by manipulating the filter[brandid] and filter[price] parameters in the /search endpoint. Attackers can inject arbitrary scripts, potentially compromising user sessions or defacing the site. The issue is publicly exploitable; an exploit has been published. Upgrading to 1.9.1.4 removes the vulnerability. No current CISA KEV listing.
Authoritative CVE Metadata - CVSS Base Score: 3.5 (LOW) - Published: 2023-08-26T09:15:09.057 - Last Modified: 2026-09-22T09:17:03.833
Original Description: A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3. The affected element is an unknown function of the file /search. This manipulation of the argument filter[brandid]/filter[price] causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version 1.9.1.4 is sufficient to fix this issue. It is advisable to upgrade the affected component.
"Our kindness may be the most persuasive argument for that which we believe."
— Gordon Hinckley