ZeroHour

CVE-2023-39648

CVSS 3.1
9.8 critical
EPSS
<1%p43
Published
()
Modified
Description

Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module “Theme Volty CMS Testimonial” (tvcmstestimonial) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

Vendors
themevolty
Products
theme volty cms testimonial
Ecosystems
E-commerce
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.