First published: Wed Mar 01 2023(Updated: )
The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method `stripejsValidationModuleFrontController::initContent()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Stripe | <4.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23315 is categorized as a high severity vulnerability due to its potential for SQL injection exploitation.
To fix CVE-2023-23315, update the Stripe Payment Pro module to a version later than 4.5.5.
CVE-2023-23315 is a Blind SQL Injection vulnerability that allows attackers to manipulate SQL queries.
CVE-2023-23315 affects Stripe Payment Pro module versions up to and including 4.5.5.
Attackers can exploit CVE-2023-23315 to execute arbitrary SQL queries against the database.