CVE-2023-25207: SQL Injection
Published Mar 13, 2023
·Updated
PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.
Affected Software
1 affected component
Prestashop Dpd France Prestashop<6.1.3
Event History
Mar 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this PrestaShop vulnerability?
The vulnerability ID for this PrestaShop vulnerability is CVE-2023-25207.
2
What is the description of the PrestaShop vulnerability?
The PrestaShop vulnerability is a SQL Injection vulnerability in dpdfrance/ajax.php.
3
What is the affected software for this vulnerability?
The affected software is PrestaShop dpd_france version up to exclusive 6.1.3.
4
What is the severity of this vulnerability?
The severity of this vulnerability is critical with a CVSS score of 9.8.
5
How can I fix this PrestaShop vulnerability?
To fix this vulnerability, upgrade the PrestaShop dpd_france module to version 6.1.3 or above.