CVE-2023-26860

SQL injection vulnerability found in PrestaShop Igbudget v.1.0.3 and before allow a remote attacker to gain privileges via the LgBudgetBudgetModuleFrontController::displayAjaxGenerateBudget component.
Configurations

Configuration 1 (hide)

cpe:2.3:a:save_your_carts_and_buy_later_or_send_it_project:save_your_carts_and_buy_later_or_send_it:*:*:*:*:*:prestashop:*:*

History

11 Feb 2025, 17:15

Type Values Removed Values Added
References (MISC) https://friends-of-presta.github.io/security-advisories/modules/2023/04/04/lgbudget.html - Exploit, Patch, Third Party Advisory () https://friends-of-presta.github.io/security-advisories/modules/2023/04/04/lgbudget.html - Exploit, Patch, Third Party Advisory
References (MISC) https://addons.prestashop.com/en/order-management/45282-save-your-carts-and-buy-later-or-send-it.html - Product () https://addons.prestashop.com/en/order-management/45282-save-your-carts-and-buy-later-or-send-it.html - Product

14 Apr 2023, 03:53

Type Values Removed Values Added
References (MISC) https://addons.prestashop.com/en/order-management/45282-save-your-carts-and-buy-later-or-send-it.html - (MISC) https://addons.prestashop.com/en/order-management/45282-save-your-carts-and-buy-later-or-send-it.html - Product
References (MISC) https://friends-of-presta.github.io/security-advisories/modules/2023/04/04/lgbudget.html - (MISC) https://friends-of-presta.github.io/security-advisories/modules/2023/04/04/lgbudget.html - Exploit, Patch, Third Party Advisory
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:save_your_carts_and_buy_later_or_send_it_project:save_your_carts_and_buy_later_or_send_it:*:*:*:*:*:prestashop:*:*
First Time Save Your Carts And Buy Later Or Send It Project
Save Your Carts And Buy Later Or Send It Project save Your Carts And Buy Later Or Send It

10 Apr 2023, 13:37

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-10 13:15

Updated : 2025-02-11 17:15


NVD link : CVE-2023-26860

Mitre link : CVE-2023-26860


JSON object : View

Products Affected

save_your_carts_and_buy_later_or_send_it_project

  • save_your_carts_and_buy_later_or_send_it
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')