First published: Fri Nov 17 2023(Updated: )
In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 5.0.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection via `exportProduct::_addDataToDb().`
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Myprestamodules Exportproducts | <5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability CVE-2023-45387 is a SQL injection vulnerability in the module Product Catalog (CSV, Excel, XML) Export PRO (exportproducts) in versions up to 5.0.0 for PrestaShop.
The vulnerability CVE-2023-45387 has a severity score of 9.8 (Critical).
A guest can exploit the vulnerability CVE-2023-45387 via the exportProduct::_addDataToDb() function.
The versions up to 5.0.0 of the Product Catalog (CSV, Excel, XML) Export PRO module for PrestaShop are affected by the vulnerability CVE-2023-45387.
To fix the vulnerability CVE-2023-45387, update the Product Catalog (CSV, Excel, XML) Export PRO module to version 5.1.1 or higher.