CVE-2023-25206: SQL Injection
Published Mar 14, 2023
·Updated
PrestaShop wsproductreviews < 3.6.2 is vulnerable to SQL Injection.
Affected Software
1 affected component
Prestashop Advanced Reviews Prestashop<3.6.2
Event History
Mar 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability with CVE-2023-25206?
The vulnerability with CVE-2023-25206 is an SQL Injection vulnerability in PrestaShop ws_productreviews version below 3.6.2.
2
How severe is the vulnerability with CVE-2023-25206?
The severity of the vulnerability with CVE-2023-25206 is high, with a severity score of 8.8.
3
What is the affected software for CVE-2023-25206?
The affected software for CVE-2023-25206 is PrestaShop ws_productreviews version below 3.6.2.
4
How can I fix the vulnerability with CVE-2023-25206?
To fix the vulnerability with CVE-2023-25206, update PrestaShop ws_productreviews to version 3.6.2 or above.
5
What is the CWE category for CVE-2023-25206?
The CWE category for CVE-2023-25206 is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).