SQL Injection Vulnerability in Product Tag Icons Pro Module for PrestaShop by MyPresta.eu
CVE-2023-46353
9.8CRITICAL
What is CVE-2023-46353?
The Product Tag Icons Pro module for PrestaShop prior to version 1.8.4 contains a vulnerability that allows unauthenticated users to execute SQL injection attacks. The issue arises from the TiconProduct::getTiconByProductAndTicon() method, which includes sensitive SQL statements that can be exploited through a simple HTTP request. This vulnerability poses a risk of unauthorized data access and manipulation, emphasizing the need for timely updates to the module to safeguard your e-commerce platform.
