CVE-2023-45376
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2023-45376 is a newly disclosed vulnerability affecting the "Carousels Pack - Instagram, Products, Brands, Supplier" module (hicarouselspack) in PrestaShop versions up to 1.5.0, developed by HiPresta. This issue allows a guest user to execute SQL injection attacks through the HiCpProductGetter::getViewedProduct() function. Successful exploitation could lead to unauthorized access to sensitive data or even complete system takeover. It is recommended that users update their PrestaShop installations to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.