SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain sensitive information via the method HsAccessoriesGroupProductAbstract::getAccessoriesByIdProducts().
                
            References
                    | Link | Resource | 
|---|---|
| https://security.friendsofpresta.org/modules/2024/02/08/hsmultiaccessoriespro.html | Patch Third Party Advisory | 
| https://security.friendsofpresta.org/modules/2024/02/08/hsmultiaccessoriespro.html | Patch Third Party Advisory | 
Configurations
                    History
                    21 Nov 2024, 08:36
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://security.friendsofpresta.org/modules/2024/02/08/hsmultiaccessoriespro.html - Patch, Third Party Advisory | 
07 Jun 2024, 14:12
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Prestamonster Prestamonster multi Accessories Pro | |
| CPE | cpe:2.3:a:prestamonster:multi_accessories_pro:*:*:*:*:*:prestashop:*:* | 
15 Feb 2024, 19:32
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Presta Monster multi Accessories Pro Presta Monster | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 9.8 | 
| CPE | cpe:2.3:a:presta_monster:multi_accessories_pro:*:*:*:*:*:prestashop:*:* | |
| References | () https://security.friendsofpresta.org/modules/2024/02/08/hsmultiaccessoriespro.html - Patch, Third Party Advisory | |
| CWE | CWE-89 | 
09 Feb 2024, 14:31
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
09 Feb 2024, 08:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-02-09 08:15
Updated : 2025-05-15 20:15
NVD link : CVE-2023-50026
Mitre link : CVE-2023-50026
CVE.ORG link : CVE-2023-50026
JSON object : View
Products Affected
                prestamonster
- multi_accessories_pro
CWE
                
                    
                        
                        CWE-89
                        
            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
