Vulnerability Description
In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design for PrestaShop, a guest can perform SQL injection in affected versions. The method `NewsletterpopsendVerificationModuleFrontController::checkEmailSubscription()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Activedesign | Newsletterpop | >= 2.3.1, <= 2.4.53 |
Related Weaknesses (CWE)
References
- https://github.com/friends-of-presta/security-advisories/blob/main/_posts/2023-1PatchThird Party Advisory
- https://github.com/friends-of-presta/security-advisories/blob/main/_posts/2023-1PatchThird Party Advisory
FAQ
What is CVE-2023-47308?
CVE-2023-47308 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design for PrestaShop, a guest can perform SQL injection in affected versions. The method...
How severe is CVE-2023-47308?
CVE-2023-47308 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-47308?
Check the references section above for vendor advisories and patch information. Affected products include: Activedesign Newsletterpop.