{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-23T00:29:39.531","vulnerabilities":[{"cve":{"id":"CVE-2023-39645","sourceIdentifier":"cve@mitre.org","published":"2023-10-03T21:15:10.240","lastModified":"2026-06-17T06:12:39.490","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper neutralization of SQL parameter in Theme Volty CMS Payment Icon module for PrestaShop. In the module “Theme Volty CMS Payment Icon” (tvcmspaymenticon) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions."},{"lang":"es","value":"Neutralización incorrecta del parámetro SQL en el módulo Theme Volty CMS Payment Icon para PrestaShop. En el módulo “Theme Volty CMS Payment Icon” (tvcmspaymenticon) hasta la versión 4.0.1 de Theme Volty para PrestaShop, un invitado puede realizar inyección SQL en las versiones afectadas."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-20T16:35:03.826771Z","id":"CVE-2023-39645","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:themevolty:cms_payment_icon:*:*:*:*:*:prestashop:*:*","versionEndExcluding":"4.0.2","matchCriteriaId":"3483A11D-8685-4477-A8BE-BE00C95AA46A"}]}]}],"references":[{"url":"https://security.friendsofpresta.org/modules/2023/09/26/tvcmspaymenticon.html","source":"cve@mitre.org","tags":["Patch","Third Party Advisory"]},{"url":"https://security.friendsofpresta.org/modules/2023/09/26/tvcmspaymenticon.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]}]}}]}