Skip to content

Commit

Permalink
Update 2023-10-25-tvcmsblog.md
Browse files Browse the repository at this point in the history
  • Loading branch information
touchweb-vincent authored Oct 25, 2023
1 parent 3ad975d commit c0d3459
Showing 1 changed file with 2 additions and 3 deletions.
5 changes: 2 additions & 3 deletions _posts/2023-10-25-tvcmsblog.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ severity: "critical (9.8)"
---
In tvcmsblog, dependancies of the theme Electron edited by Themevolty for PrestaShop, an attacker can perform a blind SQL injection.

## Summary
* **CVE ID**: [CVE-2023-27846](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27846)
Expand All @@ -25,8 +25,7 @@ In tvcmsblog, dependancies of the theme Electron edited by Themevolty for Presta
* **Severity**: critical (9.8)
## Description

Multiple sensitive SQL calls in many php classes can be executed with a trivial http call and exploited to forge a blind SQL injection throught the POST or GET submitted "rewrite", "page_type", "recordsArray" variables.

WARNING : Be warned that one exploit will bypass some WAF (hijacked unconventional HTTP header) in this [CVE-2023-39650](https://security.friendsofpresta.org/modules/2023/08/24/tvcmsblog.html)
Expand Down

0 comments on commit c0d3459

Please sign in to comment.