CVE-2023-40923: SQL Injection
Published Nov 15, 2023
·Updated
MyPrestaModules ordersexport before v5.0 was discovered to contain multiple SQL injection vulnerabilities at send.php via the key and savesetting parameters.
Affected Software
1 affected component
MyPrestaModules Orders \(csv\, Excel\) Export Pro Prestashop<5.0
Remediation
Event History
Nov 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-40923.
2
What is the severity of CVE-2023-40923?
The severity of CVE-2023-40923 is high.
3
What is the affected software of CVE-2023-40923?
The affected software of CVE-2023-40923 is MyPrestaModules ordersexport before v5.0.
4
How was the vulnerability discovered?
The vulnerability was discovered at send.php via the key and save_setting parameters.
5
Is there a fix available for CVE-2023-40923?
Yes, a fix is available for CVE-2023-40923. It is recommended to update to version 5.0 or later of MyPrestaModules ordersexport.