Vulnerability Description
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could lead to a SQL injection. This is exploited in the wild in March 2023.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tshirtecommerce | Custom Product Designer | 2.1.4 |
Related Weaknesses (CWE)
References
- https://codecanyon.net/item/prestashop-custom-product-designer/19202018Product
- https://friends-of-presta.github.io/security-advisories/module/2023/03/21/tshirtExploitPatchThird Party Advisory
- https://tshirtecommerce.com/Product
- https://codecanyon.net/item/prestashop-custom-product-designer/19202018Product
- https://friends-of-presta.github.io/security-advisories/module/2023/03/21/tshirtExploitPatchThird Party Advisory
- https://tshirtecommerce.com/Product
FAQ
What is CVE-2023-27637?
CVE-2023-27637 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to explo...
How severe is CVE-2023-27637?
CVE-2023-27637 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-27637?
Check the references section above for vendor advisories and patch information. Affected products include: Tshirtecommerce Custom Product Designer.