ZeroHour

CVE-2023-46989

CVSS 3.1
7.8 high
EPSS
<1%p14
Published
()
Modified
Description

SQL Injection vulnerability in the Innovadeluxe Quick Order module for PrestaShop before v.1.4.0, allows local attackers to execute arbitrary code via the getProducts() function in the productlist.php file.

Vendors
innovadeluxe
Products
quick order
Ecosystems
E-commerce
Weakness
CWE-89
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.