CVE ID | CVE-2023-6921 |
Publication date | 08 January 2024 |
Vendor | PrestaShow |
Product | PrestaShop Google Integrator |
Vulnerable versions | All below 2.1.4 |
Vulnerability type (CWE) | SQL injection (CWE-89) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in PrestaShow Google Integrator software and participated in its coordination. The vulnerability allows for data extraction and modification. This attack is possible via command insertion in one of the cookies. The weakness has been confirmed by the vendor and assigned the number CVE-2023-6921. The vulnerability was fixed in version 2.1.4, all below are vulnerable. All users of module version below 2.1.4 can download a free plugin update from PrestaShow account.
Credits
We thank Piotr Zdunek for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.