CVE-2023-6921
Estado: ModificadaCrítica (9.1)—
Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification. This attack is possible via command insertion in one of the cookies.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Puntuación base: 9.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.69%
- Percentil entre todas las CVEs puntuadas: 51
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-89
- CWE-89
Referencias
- https://cert.pl/en/posts/2024/01/CVE-2023-6921/
- https://cert.pl/posts/2024/01/CVE-2023-6921/
- https://prestashow.pl/pl/moduly-prestashop/28-prestashop-google-integrator-ga4-gtm-ads-remarketing.html
- https://cert.pl/en/posts/2024/01/CVE-2023-6921/
- https://cert.pl/posts/2024/01/CVE-2023-6921/
- https://prestashow.pl/pl/moduly-prestashop/28-prestashop-google-integrator-ga4-gtm-ads-remarketing.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-6921",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-6921",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-02-02T20:30:38.541018Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cvd@cert.pl",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cvd@cert.pl",
"affectedData": [
{
"vendor": "PrestaShow",
"product": "PrestaShop Google Integrator",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.1.4",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-01-08T12:15:46.513",
"references": [
{
"url": "https://cert.pl/en/posts/2024/01/CVE-2023-6921/",
"tags": [
"Third Party Advisory"
],
"source": "cvd@cert.pl"
},
{
"url": "https://cert.pl/posts/2024/01/CVE-2023-6921/",
"tags": [
"Third Party Advisory"
],
"source": "cvd@cert.pl"
},
{
"url": "https://prestashow.pl/pl/moduly-prestashop/28-prestashop-google-integrator-ga4-gtm-ads-remarketing.html",
"tags": [
"Product"
],
"source": "cvd@cert.pl"
},
{
"url": "https://cert.pl/en/posts/2024/01/CVE-2023-6921/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://cert.pl/posts/2024/01/CVE-2023-6921/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://prestashow.pl/pl/moduly-prestashop/28-prestashop-google-integrator-ga4-gtm-ads-remarketing.html",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cvd@cert.pl",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification. This attack is possible via command insertion in one of the cookies.\n"
},
{
"lang": "es",
"value": "Vulnerabilidad de inyección SQL ciega en PrestaShow Google Integrator (complemento PrestaShop) permite la extracción y modificación de datos. Este ataque es posible mediante la inserción de un comando en una de las cookies."
}
],
"lastModified": "2026-06-17T06:51:41.237",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:prestashow:google_integrator:*:*:*:*:*:prestashop:*:*",
"vulnerable": true,
"matchCriteriaId": "6C4DFC6A-D90C-4E43-980E-2404E45E7983",
"versionEndExcluding": "2.1.4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cvd@cert.pl"
}