SQL Injection Vulnerability in Product Tag Icons Pro Module for PrestaShop by MyPresta.eu
CVE-2023-46353

9.8CRITICAL

Key Information:

Vendor

Mypresta

Vendor
CVE Published:
6 December 2023

What is CVE-2023-46353?

The Product Tag Icons Pro module for PrestaShop prior to version 1.8.4 contains a vulnerability that allows unauthenticated users to execute SQL injection attacks. The issue arises from the TiconProduct::getTiconByProductAndTicon() method, which includes sensitive SQL statements that can be exploited through a simple HTTP request. This vulnerability poses a risk of unauthorized data access and manipulation, emphasizing the need for timely updates to the module to safeguard your e-commerce platform.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.