An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could lead to a SQL injection. This is exploited in the wild in March 2023.
                
            References
                    | Link | Resource | 
|---|---|
| https://codecanyon.net/item/prestashop-custom-product-designer/19202018 | Product | 
| https://friends-of-presta.github.io/security-advisories/module/2023/03/21/tshirtecommerce_cwe-89.html | Exploit Patch Third Party Advisory | 
| https://tshirtecommerce.com/ | Product | 
| https://codecanyon.net/item/prestashop-custom-product-designer/19202018 | Product | 
| https://friends-of-presta.github.io/security-advisories/module/2023/03/21/tshirtecommerce_cwe-89.html | Exploit Patch Third Party Advisory | 
| https://tshirtecommerce.com/ | Product | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 07:53
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://codecanyon.net/item/prestashop-custom-product-designer/19202018 - Product | |
| References | () https://friends-of-presta.github.io/security-advisories/module/2023/03/21/tshirtecommerce_cwe-89.html - Exploit, Patch, Third Party Advisory | |
| References | () https://tshirtecommerce.com/ - Product | 
24 Mar 2023, 04:48
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-03-22 13:15
Updated : 2025-02-26 16:15
NVD link : CVE-2023-27637
Mitre link : CVE-2023-27637
CVE.ORG link : CVE-2023-27637
JSON object : View
Products Affected
                tshirtecommerce
- custom_product_designer
CWE
                
                    
                        
                        CWE-89
                        
            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
