Vulnerability Details CVE-2023-27846
SQL injection vulnerability found in PrestaShop themevolty v.4.0.8 and before allow a remote attacker to gain privileges via the tvcmsblog, tvcmsvideotab, tvcmswishlist, tvcmsbrandlist, tvcmscategorychainslider, tvcmscategoryproduct, tvcmscategoryslider, tvcmspaymenticon, tvcmstestimonial components.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.3%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-27846
-
cpe:2.3:a:themevolty:theme_volty_cms_blog:-
-
cpe:2.3:a:themevolty:theme_volty_cms_blog:4.0.1
-
cpe:2.3:a:themevolty:theme_volty_cms_blog:4.0.8