Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7vr6-ww8j-mxp6

Опубликовано: 04 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module “Theme Volty CMS Testimonial” (tvcmstestimonial) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module “Theme Volty CMS Testimonial” (tvcmstestimonial) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

EPSS

Процентиль: 20%
0.00066
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module “Theme Volty CMS Testimonial” (tvcmstestimonial) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

EPSS

Процентиль: 20%
0.00066
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89