← Back to browse · API

CVE-2023-27638

Severity
CRITICAL
CVSS
9.8
EPSS
0.03299
Risk score
40.35
CISA KEV
No
PoC
No
Published
2023-03-22
Modified
2025-02-26
First seen
2026-08-07
Aliases
EUVD-2023-31374, GHSA-JM4Q-F3H3-J5CF
Products
n/a:n/a n/a
Sources
euvd EUVD-2023-31374

Description

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions hookActionCartSave and updateCustomizationTable, which could lead to a SQL injection. This is exploited in the wild in March 2023.

References