Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-46353


In the module "Product Tag Icons Pro" (ticons) before 1.8.4 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The method TiconProduct::getTiconByProductAndTicon() has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.


Published

2023-12-06T23:15:07.243

Last Modified

2024-11-21T08:28:21.140

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mypresta product_tag_icons_pro < 1.8.4 Yes

References