CVE-2023-45256

Multiple SQL injection vulnerabilities in the EuroInformation MoneticoPaiement module before 1.1.1 for PrestaShop allow remote attackers to execute arbitrary SQL commands via the TPE, societe, MAC, reference, or aliascb parameter to transaction.php, validation.php, or callback.php.
Configurations

No configuration.

History

17 Jun 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-89

16 Jun 2025, 12:32

Type Values Removed Values Added
Summary
  • (es) Varias vulnerabilidades de inyección SQL en el módulo EuroInformation MoneticoPaiement anterior a 1.1.1 para PrestaShop permiten a atacantes remotos ejecutar comandos SQL arbitrarios a través del parámetro TPE, societe, MAC, referencia o aliascb en transaction.php, validation.php o callback.php.

12 Jun 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-12 17:15

Updated : 2025-06-17 19:15


NVD link : CVE-2023-45256

Mitre link : CVE-2023-45256

CVE.ORG link : CVE-2023-45256


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')