First published: Thu Jun 15 2023(Updated: )
In the PrestaShop < 2.4.3 module "Length, weight or volume sell" (ailinear) there is a SQL injection vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Prestashop Prestashop | <2.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-31672 is critical with a score of 9.8.
The affected software for CVE-2023-31672 is PrestaShop < 2.4.3.
The SQL injection vulnerability in PrestaShop < 2.4.3 module Length, weight or volume sell (ailinear) allows an attacker to manipulate the database and potentially perform unauthorized actions.
Yes, a fix is available for CVE-2023-31672. It is recommended to update PrestaShop to version 2.4.3 or later to mitigate the vulnerability.
You can find more information about CVE-2023-31672 at the following link: [https://friends-of-presta.github.io/security-advisories/modules/2023/06/15/ailinear.html](https://friends-of-presta.github.io/security-advisories/modules/2023/06/15/ailinear.html).