CVE-2023-46348: SQL Injection
Published Dec 14, 2023
·Updated
SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain sensitive information via StUrls::hookActionDispatcher and StUrls::getInstanceId methods.
Affected Software
1 affected component
SunnyToo Sturls Prestashop<1.1.13
Remediation
Event History
Dec 14, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-46348?
CVE-2023-46348 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2023-46348?
To fix CVE-2023-46348, upgrade SunnyToo sturls to version 1.1.13 or later.
3
What versions of SunnyToo sturls are affected by CVE-2023-46348?
CVE-2023-46348 affects all versions of SunnyToo sturls prior to 1.1.13.
4
What are the potential impacts of exploiting CVE-2023-46348?
Exploitation of CVE-2023-46348 allows attackers to escalate privileges and access sensitive information.
5
Which methods are involved in the CVE-2023-46348 vulnerability?
CVE-2023-46348 involves SQL injection through the StUrls::hookActionDispatcher and StUrls::getInstanceId methods.