Record summary

CVE-2023-27847 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 19, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryCRITICALPrestaShop xipblog - SQL InjectionCVSS 9.8

In the blog module (xipblog), an anonymous user can perform SQL injection. Even though the module has been patched in version 2.0.1, the version number was not incremented at the time.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access and data leakage.

Remediation

Apply the latest security patches and updates from the vendor to address this vulnerability.

WeaknessesCWE-89
Authorsmastercho
Template tagstime-based-sqlicvecve2023prestashopsqlixipblogvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: html:"/xipblog"
FOFA: app="Prestashop"

Source: ProjectDiscovery

References

3