Critical severity9.8NVD Advisory· Published Dec 14, 2023· Updated Jun 17, 2026
CVE-2023-48925
CVE-2023-48925
Description
SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and obtain sensitive information via the component BaVideoTabSaveVideoModuleFrontController::run().
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Buy Addons/bavideotabdescription
<1.0.6+ 1 more
- (no CPE)range: <1.0.6
- cpe:2.3:a:buy-addons:bavideotab:*:*:*:*:*:prestashop:*:*range: <1.0.6
- Range: <1.0.6
Patches
Vulnerability mechanics
References
1- security.friendsofpresta.org/modules/2023/12/07/bavideotab.htmlnvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.