CVE-2023-46914
Last modified
CVE-2023-46914 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via ics_export.php.. EPSS estimates a 0.80% chance of exploitation in the next 30 days.
Description
SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via ics_export.php.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bookingcalendar Project | Bookingcalendar | <= 2.7.9 |
References
- https://security.friendsofpresta.org/modules/2024/02/06/bookingcalendar.htmlPatch, Third Party Advisory
- https://security.friendsofpresta.org/modules/2024/02/06/bookingcalendar.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-46914?
How severe is CVE-2023-46914?
How do I fix CVE-2023-46914?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-46892The radio frequency communication protocol being used by Mer…8.8
- CVE-2023-46894An issue discovered in esptool 4.6.2 allows attackers to vie…7.5
- CVE-2023-4690The Elementor Addon Elements plugin for WordPress is vulnera…4.3
- CVE-2023-46906juzaweb <= 3.4 is vulnerable to Incorrect Access Control, re…4.9
- CVE-2023-4691The WordPress Online Booking and Scheduling Plugin WordPress…7.2
- CVE-2023-46911There is a Cross Site Scripting (XSS) vulnerability in the c…6.1
- CVE-2023-46916Maxima Max Pro Power 1.0 486A devices allow BLE traffic repl…4.3
- CVE-2023-46918Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PL…4.6
- CVE-2023-46919Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 an…6.3
- CVE-2023-4692An out-of-bounds write flaw was found in grub2's NTFS filesy…7.8
- CVE-2023-46925Reportico 7.1.21 is vulnerable to Cross Site Scripting (XSS)…4.8
- CVE-2023-46927GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer…5.5
Are you affected by CVE-2023-46914?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
