VulnerabilityModified
CVE-2023-6921
Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification.
CRITICAL 9.1EPSS 0.69%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification. This attack is possible via command insertion in one of the cookies.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- prestashow/google integrator
- Source
- cvd@cert.pl
References
- https://cert.pl/en/posts/2024/01/CVE-2023-6921/Third Party Advisory
- https://cert.pl/posts/2024/01/CVE-2023-6921/Third Party Advisory
- https://prestashow.pl/pl/moduly-prestashop/28-prestashop-google-integrator-ga4-gtm-ads-remarketing.htmlProduct
- https://cert.pl/en/posts/2024/01/CVE-2023-6921/Third Party Advisory
- https://cert.pl/posts/2024/01/CVE-2023-6921/Third Party Advisory
- https://prestashow.pl/pl/moduly-prestashop/28-prestashop-google-integrator-ga4-gtm-ads-remarketing.htmlProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.