Prestashop cdesigner v3.1.3 to v3.1.8 was discovered to contain a code injection vulnerability via the component CdesignerSaverotateModuleFrontController::initContent().
References
Configurations
History
21 Nov 2024, 07:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://addons.prestashop.com/fr/declinaisons-personnalisation/22677-personnalisation-de-produit-product-customize.html - Product | |
References | () https://friends-of-presta.github.io/security-advisories/modules/2023/04/06/cdesigner-CWE434.html - Exploit, Patch, Third Party Advisory |
Information
Published : 2023-04-07 21:15
Updated : 2024-11-21 07:52
NVD link : CVE-2023-27033
Mitre link : CVE-2023-27033
CVE.ORG link : CVE-2023-27033
JSON object : View
Products Affected
cdesigner_project
- cdesigner
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type