Record summary

CVE-2023-39650 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 2, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryCRITICALPrestaShop Theme Volty CMS Blog - SQL InjectionCVSS 9.8

In the module 'Theme Volty CMS Blog' (tvcmsblog) up to versions 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized accessand data leakage.

Remediation

Apply the latest security patches and updates from the vendor to address this vulnerability.

WeaknessesCWE-89
Authorsmastercho
Template tagstime-based-sqlicvecve2023prestashopsqlitvcmsblogvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: html:"/tvcmsblog"

Source: ProjectDiscovery

References

3