peter bassill · operator
$ cve CVE-2023-27637 JSON

CVE-2023-27637

9.8
CRITICAL · CVSS 3.1 · EPSS 3.3% (pctl 88)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could lead to a SQL injection. This is exploited in the wild in March 2023.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.3% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploitnone known
Published2023-03-22
Last modified2026-06-17

Affected (1)

VendorProduct
tshirtecommercecustom product designer

References

→ the Explorer  ·  watch your stack  ·  NVD