Description
SQL injection vulnerability in the City Autocomplete (cityautocomplete) module from ebewe.net for PrestaShop, prior to version 1.8.12 (for PrestaShop version 1.5/1.6) or prior to 2.0.3 (for PrestaShop version 1.7), allows remote attackers to execute arbitrary SQL commands via the type, input_name. or q parameter in the autocompletion.php front controller.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 31 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-31T14:56:23.825Z
Reserved: 2023-04-07T00:00:00.000Z
Link: CVE-2023-30149
Updated: 2024-08-02T14:21:44.554Z
Status : Modified
Published: 2023-06-02T15:15:09.197
Modified: 2025-01-31T15:15:09.610
Link: CVE-2023-30149
No data.
OpenCVE Enrichment
No data.
Weaknesses