CVE-2023-46356 Information
Nov 02, 2023
cve
Description
In the module \CSV Feeds PRO\ (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop a guest can perform SQL injection. The method SearchApiCsv::getProducts() has sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.
Reference
https://security.friendsofpresta.org/modules/2023/10/26/csvfeeds-89.html
Share on: