CVE-2023-39524: PrestaShop vulnerable to boolean SQL injection in search product in BO
Impact SQL injection possible in product search field, in BO's product page
Patches 8.1.1
Found by Aleksey Solovev (Positive Technologies)
Workarounds none
References none
Other sources
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, SQL injection possible in the product search field, in BO's product page. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-39524?
CVE-2023-39524 is a vulnerability in PrestaShop which allows SQL injection in the product search field on the product page in the Back Office (BO) of the application.
How severe is the CVE-2023-39524 vulnerability?
The severity of CVE-2023-39524 is rated as critical with a CVSS score of 9.8.
Which versions of PrestaShop are affected by CVE-2023-39524?
Versions up to and including 8.1.0 are affected by CVE-2023-39524.
How can I fix the CVE-2023-39524 vulnerability?
Upgrade to version 8.1.1 of PrestaShop as it contains a patch for the CVE-2023-39524 vulnerability.
Are there any workarounds for CVE-2023-39524?
There are no known workarounds for CVE-2023-39524.