Critical severity9.8NVD Advisory· Published Feb 7, 2024· Updated Jun 17, 2026
CVE-2023-46914
CVE-2023-46914
Description
SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via ics_export.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:bookingcalendar_project:bookingcalendar:*:*:*:*:*:prestashop:*:*Range: <=2.7.9
- RM/bookingcalendardescription
- Range: <=2.7.9
Patches
Vulnerability mechanics
References
1- security.friendsofpresta.org/modules/2024/02/06/bookingcalendar.htmlnvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.