CVE-2023-46347 Scanner
CVE-2023-46347 Scanner - SQL Injection vulnerability in PrestaShop Step by Step products Pack
Used 3.5k times · 4.3k assets checked · domain, ipv4, subdomain
In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. The method `NdkSpack::getPacks()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
CVE-2023-46347 Scanner - SQL Injection vulnerability in PrestaShop Step by Step products Pack
Used 3.5k times · 4.3k assets checked · domain, ipv4, subdomain
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →