CVE-2023-26858: SQL Injection
Published Mar 31, 2023
·Updated
SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget component.
Affected Software
1 affected component
MyPrestaModules Frequently Asked Questions Page Prestashop=3.1.6
Remediation
Event History
Mar 31, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-26858?
The severity of CVE-2023-26858 is critical with a severity value of 9.8.
2
How does CVE-2023-26858 affect PrestaSHp faqs v.3.1.6?
CVE-2023-26858 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget component.
3
Which version of PrestaSHp faqs is affected by CVE-2023-26858?
CVE-2023-26858 affects version 3.1.6 of PrestaSHp faqs.
4
Is there a fix available for CVE-2023-26858?
Yes, there is a fix available for CVE-2023-26858. Please refer to the provided references for more information.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-26858?
The Common Weakness Enumeration (CWE) ID for CVE-2023-26858 is CWE-89.