CVE-2023-24763: SQL Injection
Published Mar 6, 2023
·Updated
In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0.
Affected Software
1 affected component
Prestashop Xen Forum Prestashop<2.13.0
Remediation
Event History
Mar 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this security issue in Xen Forum module for PrestaShop?
The vulnerability ID is CVE-2023-24763.
2
What is the severity rating of CVE-2023-24763?
CVE-2023-24763 has a severity rating of 8.8 (high).
3
How does this vulnerability affect PrestaShop Xen Forum module?
This vulnerability affects versions up to 2.13.0 of the PrestaShop Xen Forum module.
4
What is the CWE ID associated with CVE-2023-24763?
The CWE ID associated with CVE-2023-24763 is CWE-89 (SQL Injection).
5
Where can I find more information about this Xen Forum module vulnerability in PrestaShop?
You can find more information about this Xen Forum module vulnerability in PrestaShop in the references provided: [link1](https://addons.prestashop.com/en/blog-forum-new/19299-xen-forum.html), [link2](https://friends-of-presta.github.io/security-advisories/modules/2023/03/06/xenforum.html).