Record summary

CVE-2023-46347 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. The method `NdkSpack::getPacks()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 19, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 11, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE List, VulnCheckThrough 1.5.6affected

Nuclei templates

1
ProjectDiscoveryCRITICALPrestaShop Step by Step products Pack - SQL InjectionCVSS 9.8

In the module “Step by Step products Pack” (ndk_steppingpack) up to 1.5.6 from NDK Design for PrestaShop, a guest can perform SQL injection in affected versions.

Impact

Unauthenticated attackers can execute arbitrary SQL queries, potentially extracting sensitive database information including user credentials and payment data.

Remediation

Update the Step by Step products Pack (ndk_steppingpack) module to version 1.5.7 or later from NDK Design.

WeaknessesCWE-89
AuthorsMaStErChO
Template tagstime-based-sqlicvecve2023sqliprestashopndk_steppingpackndkdesignvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:ndkdesign:ndk_steppingpack:*:*:*:*:*:prestashop:*:*
Shodan: http.component:"prestashop"

Source: ProjectDiscovery

References

2