CVE-2023-26860

SQL injection vulnerability found in PrestaShop Igbudget v.1.0.3 and before allow a remote attacker to gain privileges via the LgBudgetBudgetModuleFrontController::displayAjaxGenerateBudget component.
Configurations

Configuration 1 (hide)

cpe:2.3:a:save_your_carts_and_buy_later_or_send_it_project:save_your_carts_and_buy_later_or_send_it:*:*:*:*:*:prestashop:*:*

History

21 Nov 2024, 07:52

Type Values Removed Values Added
References () https://addons.prestashop.com/en/order-management/45282-save-your-carts-and-buy-later-or-send-it.html - Product () https://addons.prestashop.com/en/order-management/45282-save-your-carts-and-buy-later-or-send-it.html - Product
References () https://friends-of-presta.github.io/security-advisories/modules/2023/04/04/lgbudget.html - Exploit, Patch, Third Party Advisory () https://friends-of-presta.github.io/security-advisories/modules/2023/04/04/lgbudget.html - Exploit, Patch, Third Party Advisory

14 Apr 2023, 03:53

Type Values Removed Values Added
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
First Time Save Your Carts And Buy Later Or Send It Project
Save Your Carts And Buy Later Or Send It Project save Your Carts And Buy Later Or Send It
References (MISC) https://friends-of-presta.github.io/security-advisories/modules/2023/04/04/lgbudget.html - (MISC) https://friends-of-presta.github.io/security-advisories/modules/2023/04/04/lgbudget.html - Exploit, Patch, Third Party Advisory
References (MISC) https://addons.prestashop.com/en/order-management/45282-save-your-carts-and-buy-later-or-send-it.html - (MISC) https://addons.prestashop.com/en/order-management/45282-save-your-carts-and-buy-later-or-send-it.html - Product
CPE cpe:2.3:a:save_your_carts_and_buy_later_or_send_it_project:save_your_carts_and_buy_later_or_send_it:*:*:*:*:*:prestashop:*:*

10 Apr 2023, 13:37

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-10 13:15

Updated : 2025-02-11 17:15


NVD link : CVE-2023-26860

Mitre link : CVE-2023-26860

CVE.ORG link : CVE-2023-26860


JSON object : View

Products Affected

save_your_carts_and_buy_later_or_send_it_project

  • save_your_carts_and_buy_later_or_send_it
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')