CVE Published: 08/01/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: CERT-PL |
Vendor: PrestaShow |
Product: PrestaShop Google Integrator Status : PUBLISHED
CVE-2023-6921 Description
Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification. This attack is possible via command insertion in one of the cookies.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H