CVE-2023-45386: SQL Injection
In the module extratabspro before version 2.2.8 from MyPresta.eu for PrestaShop, a guest can perform SQL injection via extratabspro::searchcategory(), extratabspro::searchproduct() and extratabspro::searchmanufacturer().'
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-45386?
CVE-2023-45386 is a vulnerability in the extratabspro module before version 2.2.8 from MyPresta.eu for PrestaShop that allows a guest to perform SQL injection.
How severe is CVE-2023-45386?
CVE-2023-45386 has a severity rating of 9.8 (Critical).
How can a guest perform SQL injection in CVE-2023-45386?
A guest can perform SQL injection in CVE-2023-45386 through the extratabspro::searchcategory(), extratabspro::searchproduct(), and extratabspro::searchmanufacturer() functions.
What software is affected by CVE-2023-45386?
PrestaShop installations using the extratabspro module before version 2.2.8 from MyPresta.eu are affected by CVE-2023-45386.
Where can I find more information about CVE-2023-45386?
You can find more information about CVE-2023-45386 at this link: https://security.friendsofpresta.org/modules/2023/10/12/extratabspro.html