---
id: CVE-2024-58304
title: >-
  SPA-CART CMS before 2.0.0 contains a stored cross-site scripting vulnerability
  in the product description parameter that allows authenticated administrators
  to inject malicious scripts
summary: >-
  SPA-CART CMS before 2.0.0 contains a stored cross-site scripting vulnerability
  in the product description parameter that allows authenticated administrators
  to inject malicious scripts. Attackers can submit JavaScript payloads through
  th…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: SPA-Cart
product: SPA-CART CMS
affected:
  - cms < 2.0.0
published: '2025-12-11'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T20:17:06.860'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-58304'
references:
  - url: 'https://github.com/olegkhorev/php-spa-cart/releases/tag/v2.0.0'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/51919'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/spa-cart-cms-stored-cross-site-scripting-via-product-description
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2025-12-18T21:41:53.701886Z'
ingestedAt: '2026-09-28T20:20:05.645Z'
---

## Overview

SPA-CART CMS before 2.0.0 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through the 'descr' parameter in the product edit form to execute arbitrary code in administrative users' browsers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
