High severity8.8NVD Advisory· Published May 4, 2023· Updated Jun 17, 2026
CVE-2023-27568
CVE-2023-27568
Description
SQL injection vulnerability inSpryker Commerce OS 0.9 that allows for access to sensitive data via customer/order?orderSearchForm[searchText]=
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
30.9+ 2 more
- (no CPE)range: 0.9
- (no CPE)
- cpe:2.3:o:spryker:commerce_os:0.9:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/172257/Spryker-Commerce-OS-1.0-SQL-Injection.htmlnvdExploitThird Party Advisory
- seclists.org/fulldisclosure/2023/May/2nvdExploitThird Party Advisory
- www.schutzwerk.com/advisories/SCHUTZWERK-SA-2023-001.txtnvdExploitThird Party Advisory
- www.schutzwerk.com/blog/schutzwerk-sa-2023-001/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.