CVE-2023-29632

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jun 6, 2023
Updated: Jan 8, 2025
CWE ID 89

Summary

CVE-2023-29632 represents a critical SQL Injection vulnerability affecting the PrestaShop jmspagebuilder 3.x. An attacker can exploit this flaw in the ajax_jmspagebuilder.php file, allowing unauthorized SQL query manipulation. This vulnerability could potentially lead to the exposure of sensitive data, such as user information and database credentials, and may enable the attacker to execute malicious commands on the affected system. It is highly recommended for PrestaShop users of jmspagebuilder 3.x to apply the necessary patches as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share