First published: Wed Jul 26 2023(Updated: )
SQL injection vulnerability found in PrestaShop sendinblue v.4.0.15 and before allow a remote attacker to gain privileges via the ajaxOrderTracking.php component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Brevo | <=4.0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-26859 is considered high due to the potential for remote privilege escalation.
To fix CVE-2023-26859, upgrade to the latest version of PrestaShop sendinblue beyond v.4.0.15.
CVE-2023-26859 affects PrestaShop sendinblue version 4.0.15 and earlier.
CVE-2023-26859 is classified as an SQL injection vulnerability.
Yes, CVE-2023-26859 can be exploited remotely through the ajaxOrderTracking.php component.