82 lines
2.5 KiB
JSON
Raw Normal View History

{
"id": "CVE-2023-39648",
"sourceIdentifier": "cve@mitre.org",
"published": "2023-10-03T22:15:10.323",
"lastModified": "2023-10-05T15:17:30.923",
"vulnStatus": "Analyzed",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module \u201cTheme Volty CMS Testimonial\u201d (tvcmstestimonial) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions."
},
{
"lang": "es",
"value": "Neutralizaci\u00f3n incorrecta del par\u00e1metro SQL en el m\u00f3dulo Theme Volty CMS Testimonial para PrestaShop. En el m\u00f3dulo \u201cTestimonio de Theme Volty CMS\u201d (tvcmstestimonial) hasta la versi\u00f3n 4.0.1 de Theme Volty para PrestaShop, un invitado puede realizar inyecci\u00f3n SQL en las versiones afectadas."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:themevolty:theme_volty_cms_testimonial:*:*:*:*:*:prestashop:*:*",
"versionEndIncluding": "4.0.1",
"matchCriteriaId": "950F64C2-BD91-4F39-822B-2EB3759CCE66"
}
]
}
]
}
],
"references": [
{
"url": "https://security.friendsofpresta.org/modules/2023/09/26/tvcmstestimonial.html",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Third Party Advisory"
]
}
]
}