CVE-2023-33663: SQL Injection
Published Aug 16, 2023
·Updated
In the module “Customization fields fee for your store” (aicustomfee) from ai-dev module for PrestaShop, an attacker can perform SQL injection up to 0.2.0. Release 0.2.1 fixed this security issue.
Affected Software
1 affected component
ai-dev Aicustomfee Prestashop<0.2.1
Event History
Aug 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-33663?
CVE-2023-33663 is classified as a critical vulnerability due to the potential for SQL injection.
2
How do I fix CVE-2023-33663?
To fix CVE-2023-33663, upgrade the 'Customization fields fee for your store' module to version 0.2.1 or later.
3
Who is affected by CVE-2023-33663?
CVE-2023-33663 affects users of the 'Customization fields fee for your store' module version up to 0.2.0 for PrestaShop.
4
What kind of attack is possible with CVE-2023-33663?
An attacker can exploit CVE-2023-33663 to perform SQL injection, potentially compromising the database.
5
Is there a patch for CVE-2023-33663?
Yes, version 0.2.1 of the 'Customization fields fee for your store' module contains a patch for CVE-2023-33663.