Vulnerability Details CVE-2023-43149
SPA-Cart 1.9.0.3 is vulnerable to Cross Site Request Forgery (CSRF) that allows a remote attacker to add an admin user with role status.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 72.6%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2023-43149
-
cpe:2.3:a:spa-cart:spa-cart:1.9.0.3