Vulnerabilities > Hipresta > Carousels Pack > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-10-19 CVE-2023-45376 SQL Injection vulnerability in Hipresta Carousels Pack 1.5.0
In the module "Carousels Pack - Instagram, Products, Brands, Supplier" (hicarouselspack) for PrestaShop up to version 1.5.0 from HiPresta for PrestaShop, a guest can perform SQL injection via HiCpProductGetter::getViewedProduct().`
network
low complexity
hipresta CWE-89
critical
9.8