CVE-2023-45387: SQL Injection
In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 5.0.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection via exportProduct::addDataToDb().
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability CVE-2023-45387?
The vulnerability CVE-2023-45387 is a SQL injection vulnerability in the module Product Catalog (CSV, Excel, XML) Export PRO (exportproducts) in versions up to 5.0.0 for PrestaShop.
How severe is the vulnerability CVE-2023-45387?
The vulnerability CVE-2023-45387 has a severity score of 9.8 (Critical).
How can a guest exploit the vulnerability CVE-2023-45387?
A guest can exploit the vulnerability CVE-2023-45387 via the exportProduct::_addDataToDb() function.
Which software versions are affected by the vulnerability CVE-2023-45387?
The versions up to 5.0.0 of the Product Catalog (CSV, Excel, XML) Export PRO module for PrestaShop are affected by the vulnerability CVE-2023-45387.
How can I fix the vulnerability CVE-2023-45387?
To fix the vulnerability CVE-2023-45387, update the Product Catalog (CSV, Excel, XML) Export PRO module to version 5.1.1 or higher.