VDB
CVE-2023-6921
CVE-2023-6921
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification. This attack is possible via command insertion in one of the cookies.
EPSS 0.69% · 51.5th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.69%
51.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| prestashow | google_integrator | 0, 0, 0 |
| PrestaShow | PrestaShop Google Integrator | 0, 0 |
Timeline
- Jan 8, 2024 CVE Published
- Jan 8, 2024 PoC Published
- Jan 10, 2024 EPSS Score
- Jan 25, 2024 PoC Published
- Feb 8, 2024 EPSS Score
- Mar 7, 2024 EPSS Score
- Apr 5, 2024 EPSS Score
- May 4, 2024 EPSS Score
- Jun 2, 2024 EPSS Score
- Jun 30, 2024 EPSS Score
- Jul 29, 2024 EPSS Score
- Aug 27, 2024 EPSS Score
References
- https://cert.pl/posts/2024/01/CVE-2023-6921/ url
- https://prestashow.pl/pl/moduly-prestashop/28-prestashop-google-integrator-ga4-gtm-ads-remarketing.html url
- https://cert.pl/en/posts/2024/01/CVE-2023-6921/ advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-6921 advisory
- https://cert.pl/en/posts/2024/01/CVE-2023-6921 url
- https://cert.pl/posts/2024/01/CVE-2023-6921 url