Critical severity9.8NVD Advisory· Published Jan 19, 2024· Updated Jun 17, 2026
CVE-2023-46351
CVE-2023-46351
Description
In the module mib < 1.6.1 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The methods mib::getManufacturersByCategory() has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:mypresta:manufacturers_\(brands\)_images_block:*:*:*:*:*:prestashop:*:*Range: <1.6.1
(expand)+ 1 more
- (no CPE)
- (no CPE)range: <1.6.1
Patches
Vulnerability mechanics
References
2- security.friendsofpresta.org/modules/2024/01/18/mib.htmlnvdPatchThird Party Advisory
- mypresta.eu/modules/front-office-features/manufacturers-brands-images-block.htmlnvdProduct
News mentions
0No linked articles in our index yet.