CVE-2023-23315: SQL Injection
The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method stripejsValidationModuleFrontController::initContent() has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23315?
CVE-2023-23315 is categorized as a high severity vulnerability due to its potential for SQL injection exploitation.
How do I fix CVE-2023-23315?
To fix CVE-2023-23315, update the Stripe Payment Pro module to a version later than 4.5.5.
What kind of vulnerability is CVE-2023-23315?
CVE-2023-23315 is a Blind SQL Injection vulnerability that allows attackers to manipulate SQL queries.
Which versions of the Stripe Payment Pro module are affected by CVE-2023-23315?
CVE-2023-23315 affects Stripe Payment Pro module versions up to and including 4.5.5.
What can attackers do with CVE-2023-23315?
Attackers can exploit CVE-2023-23315 to execute arbitrary SQL queries against the database.