CVE-2023-6921

Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification. This attack is possible via command insertion in one of the cookies.
Configurations

Configuration 1 (hide)

cpe:2.3:a:prestashow:google_integrator:*:*:*:*:*:prestashop:*:*

History

11 Jan 2024, 20:57

Type Values Removed Values Added
References () https://cert.pl/en/posts/2024/01/CVE-2023-6921/ - () https://cert.pl/en/posts/2024/01/CVE-2023-6921/ - Third Party Advisory
References () https://cert.pl/posts/2024/01/CVE-2023-6921/ - () https://cert.pl/posts/2024/01/CVE-2023-6921/ - Third Party Advisory
References () https://prestashow.pl/pl/moduly-prestashop/28-prestashop-google-integrator-ga4-gtm-ads-remarketing.html - () https://prestashow.pl/pl/moduly-prestashop/28-prestashop-google-integrator-ga4-gtm-ads-remarketing.html - Product
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
First Time Prestashow
Prestashow google Integrator
CPE cpe:2.3:a:prestashow:google_integrator:*:*:*:*:*:prestashop:*:*
CWE CWE-89

08 Jan 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-08 12:15

Updated : 2024-01-11 20:57


NVD link : CVE-2023-6921

Mitre link : CVE-2023-6921


JSON object : View

Products Affected

prestashow

  • google_integrator
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')