Aller au contenu

Fiche vulnérabilité

CVE-2023-27637 : faille critique tshirtecommerce custom product designer (CVSS 9.8)

Description

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could lead to a SQL injection. This is exploited in the wild in March 2023.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
22 mars 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • tshirtecommerce custom product designer

Références

Rechercher une autre vulnérabilité dans la base CVE