Critical severity9.8NVD Advisory· Published Apr 26, 2023· Updated Jun 17, 2026
CVE-2023-27843
CVE-2023-27843
Description
SQL injection vulnerability found in PrestaShop askforaquote v.5.4.2 and before allow a remote attacker to gain privileges via the QuotesProduct::deleteProduct component.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<=5.4.2+ 1 more
- (no CPE)range: <=5.4.2
- (no CPE)
- cpe:2.3:a:ask_for_a_quote_project:ask_for_a_quote:*:*:*:*:*:prestashop:*:*Range: <=5.4.2
Patches
Vulnerability mechanics
References
2- friends-of-presta.github.io/security-advisories/modules/2023/04/25/askforaquote.htmlnvdExploitPatchThird Party Advisory
- addons.prestashop.com/en/quotes/3725-ask-for-a-quote-convert-to-order-messaging-system.htmlnvdProduct
News mentions
0No linked articles in our index yet.