Vulnerability Description
In the module "CSV Feeds PRO" (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop, a guest can perform SQL injection. The method `SearchApiCsv::getProducts()` has sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Blmodules | Csv Feeds Pro | < 2.6.1 |
Related Weaknesses (CWE)
References
- https://security.friendsofpresta.org/modules/2023/10/26/csvfeeds-89.htmlExploitPatchThird Party Advisory
- https://security.friendsofpresta.org/modules/2023/10/26/csvfeeds-89.htmlExploitPatchThird Party Advisory
FAQ
What is CVE-2023-46356?
CVE-2023-46356 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In the module "CSV Feeds PRO" (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop, a guest can perform SQL injection. The method `SearchApiCsv::getProducts()` has sensitive SQL call that can be exe...
How severe is CVE-2023-46356?
CVE-2023-46356 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-46356?
Check the references section above for vendor advisories and patch information. Affected products include: Blmodules Csv Feeds Pro.