CVE-2023-27032
idnovate popup_module_\(on_entering\,_exit_popup\,_add_product\)_and_newsletter Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2023-27032 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups().
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 15, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
popup_module_\(on_entering\,_exit_popup\,_add_product\)_and_newsletterBrowse idnovate / popup_module_\(on_entering\,_exit_popup\,_add_product\)_and_newsletter | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALPrestaShop AdvancedPopupCreator - SQL InjectionCVSS 9.8
In the module “Advanced Popup Creator” (advancedpopupcreator) from Idnovate for PrestaShop, a guest can perform SQL injection in affected versions.
Impact
Unauthenticated attackers can execute arbitrary SQL commands to extract database contents including customer data, orders, payment information, and administrative credentials from the PrestaShop database.
Remediation
Upgrade to the latest version of the Advanced Popup Creator module from Idnovate that addresses this SQL injection vulnerability.
Source: ProjectDiscovery