AmazCart CMS 3.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search functionality. Attackers can enter script tags in the search box to execute arbitrary JavaScript that fires when search history is viewed or results are displayed.
Metrics
Affected Vendors & Products
References
History
Tue, 05 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AmazCart CMS 3.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search functionality. Attackers can enter script tags in the search box to execute arbitrary JavaScript that fires when search history is viewed or results are displayed. | |
| Title | AmazCart CMS 3.4 Reflected Cross-Site Scripting via Search | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-05T14:53:45.706Z
Reserved: 2026-01-10T01:51:52.986Z
Link: CVE-2023-54349
Updated: 2026-05-05T14:53:30.795Z
Status : Received
Published: 2026-05-05T12:16:17.440
Modified: 2026-05-05T12:16:17.440
Link: CVE-2023-54349
No data.
OpenCVE Enrichment
Updated: 2026-05-05T12:30:24Z