In the module "Carousels Pack - Instagram, Products, Brands, Supplier" (hicarouselspack) for PrestaShop up to version 1.5.0 from HiPresta for PrestaShop, a guest can perform SQL injection via HiCpProductGetter::getViewedProduct().`
References
Configurations
History
21 Nov 2024, 08:26
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-19 20:15
Updated : 2024-11-21 08:26
NVD link : CVE-2023-45376
Mitre link : CVE-2023-45376
CVE.ORG link : CVE-2023-45376
JSON object : View
Products Affected
hipresta
- carousels_pack
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')