SQL Injection Vulnerability in Extratabspro Module for PrestaShop
CVE-2023-45386
9.8CRITICAL
What is CVE-2023-45386?
The Extratabspro module for PrestaShop, specifically versions prior to 2.2.8, is susceptible to SQL injection attacks through methods such as extratabspro::searchcategory(), extratabspro::searchproduct(), and extratabspro::searchmanufacturer(). This vulnerability allows unauthorized guests to manipulate database queries, potentially leading to data leakage or unauthorized access to sensitive information within the e-commerce platform.
