CVE-2023-46357: SQL Injection
In the module "Cross Selling in Modal Cart" (motivationsale) < 3.5.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method motivationsaleDataModel::getProductsByIds() has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-46357.
What is the severity level of CVE-2023-46357?
CVE-2023-46357 has a severity level of 9.8 (Critical).
What is the affected software of CVE-2023-46357?
The affected software of CVE-2023-46357 is Myprestamodules Cross Selling In Modal Cart version up to exclusive 3.5.0 for PrestaShop.
How can a guest perform SQL injection using CVE-2023-46357?
A guest can perform SQL injection using CVE-2023-46357 by exploiting sensitive SQL calls in the `motivationsaleDataModel::getProductsByIds()` method of the Cross Selling in Modal Cart module.
Are there any references or resources for CVE-2023-46357?
Yes, you can find more information about CVE-2023-46357 in the following references: [link1](https://addons.prestashop.com/fr/ventes-croisees-packs-produits/16122-cross-selling-in-modal-cart.html), [link2](https://security.friendsofpresta.org/modules/2023/11/21/motivationsale.html).