NA

CVE-2023-46989

Published: 28/12/2023 Updated: 04/01/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

SQL Injection vulnerability in the Innovadeluxe Quick Order module for PrestaShop before v.1.4.0, allows local malicious users to execute arbitrary code via the getProducts() function in the productlist.php file.

Vulnerable Product Search on Vulmon Subscribe to Product

innovadeluxe quick order