CVE-2023-46914: SQL Injection
Published Feb 7, 2024
·Updated
SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via icsexport.php.
Affected Software
1 affected component
Bookingcalendar Project Bookingcalendar Prestashop<=2.7.9
Remediation
Event History
Feb 7, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-46914?
CVE-2023-46914 is a critical severity SQL Injection vulnerability allowing remote code execution and privilege escalation.
2
How do I fix CVE-2023-46914?
To fix CVE-2023-46914, upgrade the RM bookingcalendar module to version 2.7.10 or later.
3
What versions of PrestaShop are affected by CVE-2023-46914?
CVE-2023-46914 affects PrestaShop versions 2.7.9 and earlier.
4
What type of attack does CVE-2023-46914 facilitate?
CVE-2023-46914 facilitates SQL Injection attacks, allowing attackers to execute arbitrary code.
5
What files are involved in the CVE-2023-46914 vulnerability?
The vulnerability primarily involves the ics_export.php file in the RM bookingcalendar module.