SQL injection vulnerability in the City Autocomplete (cityautocomplete) module from ebewe.net for PrestaShop, prior to version 1.8.12 (for PrestaShop version 1.5/1.6) or prior to 2.0.3 (for PrestaShop version 1.7), allows remote attackers to execute arbitrary SQL commands via the type, input_name. or q parameter in the autocompletion.php front controller.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 31 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-31T14:56:23.825Z
Reserved: 2023-04-07T00:00:00.000Z
Link: CVE-2023-30149
Updated: 2024-08-02T14:21:44.554Z
Status : Modified
Published: 2023-06-02T15:15:09.197
Modified: 2025-01-31T15:15:09.610
Link: CVE-2023-30149
No data.
OpenCVE Enrichment
No data.
Weaknesses