S
QL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain sensitive information via the method HsAccessoriesGroupProductAbstract::getAccessoriesByIdProducts().
References
| Link | Resource |
|---|---|
| https://security.friendsofpresta.org/modules/2024/02/08/hsmultiaccessoriespro.html | Patch Third Party Advisory |
| https://security.friendsofpresta.org/modules/2024/02/08/hsmultiaccessoriespro.html | Patch Third Party Advisory |
Configurations
History
21 Nov 2024, 08:36
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://security.friendsofpresta.org/modules/2024/02/08/hsmultiaccessoriespro.html - Patch, Third Party Advisory |
07 Jun 2024, 14:12
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:prestamonster:multi_accessories_pro:*:*:*:*:*:prestashop:*:* | |
| First Time |
Prestamonster multi Accessories Pro
Prestamonster |
Information
Published : 2024-02-09 08:15
Updated : 2025-05-15 20:15
NVD link : CVE-2023-50026
Mitre link : CVE-2023-50026
CVE.ORG link : CVE-2023-50026
JSON object : View
Products Affected
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')