Security Advisory

CVE-2023-45376

9.8
CRITICAL

Vulnerability Description

In the module "Carousels Pack - Instagram, Products, Brands, Supplier" (hicarouselspack) for PrestaShop up to version 1.5.0 from HiPresta for PrestaShop, a guest can perform SQL injection via HiCpProductGetter::getViewedProduct().`
Published Date October 19, 2023
Official Source NIST NVD Advisory