Lucene search

K
cveMitreCVE-2023-45375
HistoryOct 17, 2023 - 5:15 a.m.

CVE-2023-45375

2023-10-1705:15:50
CWE-89
mitre
web.nvd.nist.gov
32
cve-2023-45375
sql injection
pireospay
prestashop
nvd

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9

Confidence

High

EPSS

0.047

Percentile

92.8%

In the module “PireosPay” (pireospay) before version 1.7.10 from 01generator.com for PrestaShop, a guest can perform SQL injection via PireosPayValidationModuleFrontController::postProcess().

Affected configurations

Nvd
Node
01generatorpireospayRange<1.7.10prestashop
VendorProductVersionCPE
01generatorpireospay*cpe:2.3:a:01generator:pireospay:*:*:*:*:*:prestashop:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9

Confidence

High

EPSS

0.047

Percentile

92.8%

Related for CVE-2023-45375