First published: Mon Mar 06 2023(Updated: )
In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Prestashop Xen Forum | <2.13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-24763.
CVE-2023-24763 has a severity rating of 8.8 (high).
This vulnerability affects versions up to 2.13.0 of the PrestaShop Xen Forum module.
The CWE ID associated with CVE-2023-24763 is CWE-89 (SQL Injection).
You can find more information about this Xen Forum module vulnerability in PrestaShop in the references provided: [link1](https://addons.prestashop.com/en/blog-forum-new/19299-xen-forum.html), [link2](https://friends-of-presta.github.io/security-advisories/modules/2023/03/06/xenforum.html).