CVE-2023-6921 CRITICAL

CVE-2023-6921: SQL Injection in PrestaShop Google Integrator

Vendor Prestashow
Product PrestaShop Google Integrator
Weakness CWE-89 · SQLi
Published January 8, 2024
Last update June 16, 2025

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification. This attack is possible via command insertion in one of the cookies.

Key dates

02Disclosure timeline

January 8, 2024 CVE published
June 16, 2025 Record updated