In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0.
2023-03-06T20:15:09.797
2025-03-07T17:15:17.230
Modified
CVSSv3.1: 8.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | prestashop | xen_forum | < 2.13.0 | Yes |