CVE-2023-26859: SQL Injection
Published Jul 26, 2023
·Updated
SQL injection vulnerability found in PrestaShop sendinblue v.4.0.15 and before allow a remote attacker to gain privileges via the ajaxOrderTracking.php component.
Affected Software
1 affected component
Brevo Brevo<=4.0.15
Remediation
Event History
Jul 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-26859?
The severity of CVE-2023-26859 is considered high due to the potential for remote privilege escalation.
2
How do I fix CVE-2023-26859?
To fix CVE-2023-26859, upgrade to the latest version of PrestaShop sendinblue beyond v.4.0.15.
3
What products are affected by CVE-2023-26859?
CVE-2023-26859 affects PrestaShop sendinblue version 4.0.15 and earlier.
4
What type of vulnerability is CVE-2023-26859?
CVE-2023-26859 is classified as an SQL injection vulnerability.
5
Can CVE-2023-26859 be exploited remotely?
Yes, CVE-2023-26859 can be exploited remotely through the ajaxOrderTracking.php component.