Security Advisory

CVE-2023-27637

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-03-22 00:00:00
Last updated 2025-02-26 15:40:22
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could lead to a SQL injection. This is exploited in the wild in March 2023.