CVE-2023-6921: SQL Injection in PrestaShop Google Integrator
Published Jan 8, 2024
·Updated
Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification. This attack is possible via command insertion in one of the cookies.
Affected Software
1 affected component
PrestaShow Google Integrator Prestashop<2.1.4
Event History
Jan 8, 2024
CVE Published
via MITRE·11:34 AM
Data Sourced
via MITRE·11:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-6921?
CVE-2023-6921 is classified as a high-severity blind SQL injection vulnerability.
2
How do I fix CVE-2023-6921?
To fix CVE-2023-6921, update the PrestaShow Google Integrator to version 2.1.4 or later.
3
What software is affected by CVE-2023-6921?
CVE-2023-6921 affects PrestaShow Google Integrator versions prior to 2.1.4.
4
What type of attack is possible with CVE-2023-6921?
CVE-2023-6921 allows for data extraction and modification through blind SQL injection.
5
How is the attack executed in CVE-2023-6921?
The attack for CVE-2023-6921 is executed via command insertion in one of the cookies.