Home

Description

Multiple SQL injection vulnerabilities in the EuroInformation MoneticoPaiement module before 1.1.1 for PrestaShop allow remote attackers to execute arbitrary SQL commands via the TPE, societe, MAC, reference, or aliascb parameter to transaction.php, validation.php, or callback.php.

PUBLISHED Reserved 2023-10-06 | Published 2025-06-12 | Updated 2025-06-17 | Assigner mitre

References

www.monetico-paiement.fr/...tabi=I0&_pid=ValidateLicencePage

security.friendsofpresta.org/.../06/10/MoneticoPaiement.html

cve.org (CVE-2023-45256)

nvd.nist.gov (CVE-2023-45256)

Download JSON