CVE-2023-46347
ndkdesign ndk_steppingpack Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2023-46347 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. The method `NdkSpack::getPacks()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 19, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 11, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ndk_steppingpackBrowse ndkdesign / ndk_steppingpackDefault status: unknown | CVE List, VulnCheck | Through 1.5.6 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALPrestaShop Step by Step products Pack - SQL InjectionCVSS 9.8
In the module “Step by Step products Pack” (ndk_steppingpack) up to 1.5.6 from NDK Design for PrestaShop, a guest can perform SQL injection in affected versions.
Impact
Unauthenticated attackers can execute arbitrary SQL queries, potentially extracting sensitive database information including user credentials and payment data.
Remediation
Update the Step by Step products Pack (ndk_steppingpack) module to version 1.5.7 or later from NDK Design.
Source: ProjectDiscovery