CVE-2023-43985: SQL Injection
Published Jan 19, 2024
·Updated
SunnyToo stblogsearch up to v1.0.0 was discovered to contain a SQL injection vulnerability via the StBlogSearchClass::prepareSearch component.
Affected Software
1 affected component
SunnyToo Stblogsearch Prestashop<=1.0.0
Remediation
Event History
Jan 19, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-43985?
CVE-2023-43985 is classified with a high severity due to its potential for SQL injection exploitation.
2
How do I fix CVE-2023-43985?
To fix CVE-2023-43985, update SunnyToo Stblogsearch to version 1.0.1 or later.
3
What component is vulnerable in CVE-2023-43985?
The StBlogSearchClass::prepareSearch component is vulnerable in CVE-2023-43985.
4
What type of vulnerability is CVE-2023-43985?
CVE-2023-43985 is a SQL injection vulnerability that can allow unauthorized access to the database.
5
Which versions of SunnyToo Stblogsearch are affected by CVE-2023-43985?
SunnyToo Stblogsearch versions up to and including 1.0.0 are affected by CVE-2023-43985.