CVE-2023-39524
Description
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, SQL injection possible in the product search field, in BO's product page. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
CWE
- CWE-89 — CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Affected
- PrestaShop / PrestaShop — v=< 8.1.1 [affected]
CVSS
- 3.1 score=6.7 severity=MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
References
- https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-75p5-jwx4-qw9h x_refsource_CONFIRM
- https://github.com/PrestaShop/PrestaShop/commit/2047d4c053043102bc46a37d383b392704bf14d7 x_refsource_MISC
Source
cvelistV5-main/cves/2023/39xxx/CVE-2023-39524.json