PrestaShop是美国PrestaShop公司的一套开源的电子商务解决方案。该方案提供多种支付方式、短消息提醒和商品图片缩放等功能。 PrestaShop tshirtecommerce 2.1.4版本存在安全漏洞,该漏洞源于。可以使用受损的product_id GET参数伪造HTTP请求,以利用前端控制器文件designer.php中的不安全参数,这可能导致SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The tshirtecommerce module for PrestaShop is vulnerable to unauthenticated SQL injection via the designer endpoint, allowing attackers to execute arbitrary SQL queries and extract sensitive information from the database. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-27637.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-1571 | 6.3 MEDIUM | DataGear pagingQueryData sql injection |
| CVE-2023-1558 | 6.3 MEDIUM | Simple and Beautiful Shopping Cart System uploadera.php unrestricted upload |
| CVE-2023-1565 | 3.5 LOW | FeiFeiCMS Extension Tool slide_add.html cross site scripting |
| CVE-2023-1573 | 3.5 LOW | DataGear Graph Dataset cross site scripting |
| CVE-2023-1560 | 2.8 LOW | TinyTIFF File tinytiffreader.c buffer overflow |
| CVE-2023-1572 | 2.0 LOW | DataGear Plugin cross site scripting |
| CVE-2023-28667 | WordPress Plugin Lead Generated 代码问题漏洞 | |
| CVE-2023-28666 | WordPress plugin InPost Gallery 跨站脚本漏洞 | |
| CVE-2023-28665 | WordPress plugin Woo Bulk Price Update 跨站脚本漏洞 | |
| CVE-2023-28664 | WordPress plugin Meta Data and Taxonomies Filter 跨站脚本漏洞 | |
| CVE-2023-28663 | WordPress Plugin Formidable PRO2PDF SQL注入漏洞 | |
| CVE-2023-28662 | WordPress Plugin Gift Cards SQL注入漏洞 | |
| CVE-2023-28661 | WordPress Plugin WP Popup Banners SQL注入漏洞 | |
| CVE-2023-28660 | WordPress Plugin Events Made Easy SQL注入漏洞 | |
| CVE-2023-28659 | WordPress Plugin Waiting SQL注入漏洞 | |
| CVE-2023-27754 | vox2mesh 缓冲区错误漏洞 | |
| CVE-2023-27638 | PrestaShop SQL注入漏洞 | |
| CVE-2023-27224 | NginxProxyManager 命令注入漏洞 | |
| CVE-2023-27100 | pfSense 安全漏洞 | |
| CVE-2023-27060 | LightCMS 安全漏洞 |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet