CVE-2023-39650
PrestaShop Theme Volty CMS Blog - SQL Injection
Record summary
CVE-2023-39650 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 2, 2024 · Source: CVE List
Nuclei templates
1ProjectDiscoveryCRITICALPrestaShop Theme Volty CMS Blog - SQL InjectionCVSS 9.8
In the module 'Theme Volty CMS Blog' (tvcmsblog) up to versions 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized accessand data leakage.
Remediation
Apply the latest security patches and updates from the vendor to address this vulnerability.
Source: ProjectDiscovery