← Back to browse · API

CVE-2023-27637

Severity
CRITICAL
CVSS
9.8
EPSS
0.03299
Risk score
40.35
CISA KEV
No
PoC
No
Published
2023-03-22
Modified
2025-02-26
First seen
2026-08-07
Aliases
EUVD-2023-31373, GHSA-C9QP-JR36-5VXW
Products
n/a:n/a n/a
Sources
euvd EUVD-2023-31373

Description

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could lead to a SQL injection. This is exploited in the wild in March 2023.

References