CVE-2023-36263EPSS p39.1%
CVE-2023-36263CVE-2023-36263
store-opart / op\'art_limit_quantity
Description
Prestashop opartlimitquantity 1.4.5 and before is vulnerable to SQL Injection. OpartlimitquantityAlertlimitModuleFrontController::displayAjaxPushAlertMessage()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.48% probability of exploitation · percentile 39.1% · 2026-08-03T12:00:16Z |
| Last modified | 2026-06-12 |