SQL Injection vulnerability in the Innovadeluxe Quick Order module for PrestaShop before v.1.4.0, allows local attackers to execute arbitrary code via the getProducts() function in the productlist.php file.
History

Thu, 26 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-12-28T00:00:00.000Z

Updated: 2024-09-12T18:44:14.839Z

Reserved: 2023-10-30T00:00:00.000Z

Link: CVE-2023-46989

cve-icon Vulnrichment

Updated: 2024-08-02T21:01:22.156Z

cve-icon NVD

Status : Modified

Published: 2023-12-28T06:15:44.227

Modified: 2024-11-21T08:29:35.957

Link: CVE-2023-46989

cve-icon Redhat

No data.