RSS   Vulnerabilities for 'Product tag icons pro'   RSS

2023-12-06
 
CVE-2023-46353

CWE-89
 

 
In the module "Product Tag Icons Pro" (ticons) before 1.8.4 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The method TiconProduct::getTiconByProductAndTicon() has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

 

 >>> Vendor: Mypresta 2 Products
Customer photo gallery
Product tag icons pro


Copyright 2024, cxsecurity.com

 

Back to Top