High severity8.8NVD Advisory· Published May 4, 2023· Updated Jun 17, 2026
CVE-2023-27568
CVE-2023-27568
Description
SQL injection vulnerability inSpryker Commerce OS 0.9 that allows for access to sensitive data via customer/order?orderSearchForm[searchText]=
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Spryker/Commerce OSdescription
- Range: 0.9
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/172257/Spryker-Commerce-OS-1.0-SQL-Injection.htmlnvdExploitThird Party Advisory
- seclists.org/fulldisclosure/2023/May/2nvdExploitThird Party Advisory
- www.schutzwerk.com/advisories/SCHUTZWERK-SA-2023-001.txtnvdExploitThird Party Advisory
- www.schutzwerk.com/blog/schutzwerk-sa-2023-001/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.