CVE-2023-33663
https://notcve.org/view.php?id=CVE-2023-33663
In the module “Customization fields fee for your store” (aicustomfee) from ai-dev module for PrestaShop, an attacker can perform SQL injection up to 0.2.0. Release 0.2.1 fixed this security issue. • https://security.friendsofpresta.org/modules/2023/08/16/aicustomfee.html https://www.boutique.ai-dev.fr/en/customization/62-customization-fee.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-33666
https://notcve.org/view.php?id=CVE-2023-33666
ai-dev aioptimizedcombinations before v0.1.3 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php. • https://security.friendsofpresta.org/modules/2023/08/03/aioptimizedcombinations.html https://www.boutique.ai-dev.fr/en/ergonomie/59-optimized-combinations.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-33665
https://notcve.org/view.php?id=CVE-2023-33665
ai-dev aitable before v0.2.2 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php. Se ha descubierto que las versiones anteriores a v0.2.2 de aitable de ai-dev contiene una vulnerabilidad de inyección SQL a través del componente /includes/ajax.php. • https://security.friendsofpresta.org/modules/2023/08/01/aitable.html https://www.boutique.ai-dev.fr/en/ergonomie/56-table-attributes.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-33664
https://notcve.org/view.php?id=CVE-2023-33664
ai-dev aicombinationsonfly before v0.3.1 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php. • https://security.friendsofpresta.org/modules/2023/06/28/aicombinationsonfly.html https://www.boutique.ai-dev.fr/en/ergonomie/61-combinations-on-fly.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •