PT-2023-29970 · Prestashop · Product Catalog (Csv

CVE-2023-46349

·

Publicado

2023-11-27

·

Atualizado

2023-12-01

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PrestaShop module "Product Catalog (CSV, Excel) Export/Update" versions prior to 3.8.5
Description The issue allows a guest to perform SQL injection due to sensitive SQL calls in the productsUpdateModel::getExportIds() method. This can be exploited with a trivial HTTP call, enabling the forging of a SQL injection.
Recommendations For versions prior to 3.8.5, consider disabling the productsUpdateModel::getExportIds() method until a patch is available to prevent SQL injection exploitation.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-46349

Produtos afetados

Product Catalog (Csv