CVE-2023-6921

Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification. This attack is possible via command insertion in one of the cookies.
Configurations

Configuration 1 (hide)

cpe:2.3:a:prestashow:google_integrator:*:*:*:*:*:prestashop:*:*

History

21 Nov 2024, 08:44

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.1
v2 : unknown
v3 : 9.8
References () https://cert.pl/en/posts/2024/01/CVE-2023-6921/ - Third Party Advisory () https://cert.pl/en/posts/2024/01/CVE-2023-6921/ - Third Party Advisory
References () https://cert.pl/posts/2024/01/CVE-2023-6921/ - Third Party Advisory () https://cert.pl/posts/2024/01/CVE-2023-6921/ - Third Party Advisory
References () https://prestashow.pl/pl/moduly-prestashop/28-prestashop-google-integrator-ga4-gtm-ads-remarketing.html - Product () https://prestashow.pl/pl/moduly-prestashop/28-prestashop-google-integrator-ga4-gtm-ads-remarketing.html - Product

11 Jan 2024, 20:57

Type Values Removed Values Added
References () https://cert.pl/en/posts/2024/01/CVE-2023-6921/ - () https://cert.pl/en/posts/2024/01/CVE-2023-6921/ - Third Party Advisory
References () https://prestashow.pl/pl/moduly-prestashop/28-prestashop-google-integrator-ga4-gtm-ads-remarketing.html - () https://prestashow.pl/pl/moduly-prestashop/28-prestashop-google-integrator-ga4-gtm-ads-remarketing.html - Product
References () https://cert.pl/posts/2024/01/CVE-2023-6921/ - () https://cert.pl/posts/2024/01/CVE-2023-6921/ - Third Party Advisory
CPE cpe:2.3:a:prestashow:google_integrator:*:*:*:*:*:prestashop:*:*
First Time Prestashow google Integrator
Prestashow
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

08 Jan 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-08 12:15

Updated : 2024-11-21 08:44


NVD link : CVE-2023-6921

Mitre link : CVE-2023-6921

CVE.ORG link : CVE-2023-6921


JSON object : View

Products Affected

prestashow

  • google_integrator
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')