Report an incident
Report an incident

Vulnerability in PrestaShop Google Integrator software
08 January 2024 | CERT Polska | #vulnerability, #warning, #cve
CVE ID CVE-2023-6921
Publication date 08 January 2024
Vendor PrestaShow
Product PrestaShop Google Integrator
Vulnerable versions All below 2.1.4
Vulnerability type (CWE) SQL injection (CWE-89)
Report source Report to CERT Polska

Description

CERT Polska has received a report about vulnerability in PrestaShow Google Integrator software and participated in its coordination. The vulnerability allows for data extraction and modification. This attack is possible via command insertion in one of the cookies. The weakness has been confirmed by the vendor and assigned the number CVE-2023-6921. The vulnerability was fixed in version 2.1.4, all below are vulnerable. All users of module version below 2.1.4 can download a free plugin update from PrestaShow account.

Credits

We thank Piotr Zdunek for the responsible vulnerability report.


More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.