CVE-2023-27844: SQL Injection
Published Apr 17, 2023
·Updated
SQL injection vulnerability found in PrestaShopleurlrewrite v.1.0 and before allow a remote attacker to gain privileges via the Dispatcher::getController component.
Affected Software
1 affected component
Litextension Leurlrewrite Prestashop<=1.0
Remediation
Event History
Apr 17, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-27844?
The severity of CVE-2023-27844 is considered to be high due to its potential to allow remote attackers to gain privileges.
2
How do I fix CVE-2023-27844?
To fix CVE-2023-27844, you should update the PrestaShopleurlrewrite module to version 1.1 or later.
3
Who is affected by CVE-2023-27844?
CVE-2023-27844 affects users of the PrestaShopleurlrewrite module version 1.0 and earlier.
4
What type of vulnerability is CVE-2023-27844?
CVE-2023-27844 is an SQL injection vulnerability that can be exploited by remote attackers.
5
What component is involved in CVE-2023-27844?
The Dispatcher::getController component is involved in the CVE-2023-27844 vulnerability.