Vulnerability Details CVE-2023-39646
Improper neutralization of SQL parameter in Theme Volty CMS Category Chain Slider module for PrestaShop. In the module “Theme Volty CMS Category Chain Slide"(tvcmscategorychainslider) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 40.8%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-39646
-
cpe:2.3:a:themevolty:theme_volty_cms_category_chain_slider:4.0.1