CVE-2023-45381

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
19/10/2023
Last modified:
25/10/2023

Description

In the module "Creative Popup" (creativepopup) up to version 1.6.9 from WebshopWorks for PrestaShop, a guest can perform SQL injection via `cp_download_popup().`

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:webshopworks:creativepopup:*:*:*:*:*:prestashop:*:* 1.6.10 (excluding)