ZeroHour

CVE-2023-46914

CVSS 3.1
9.8 critical
EPSS
<1%p54
Published
()
Modified
Description

SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via ics_export.php.

Vendors
bookingcalendar project
Products
bookingcalendar
Ecosystems
E-commerce
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.