CVE-2023-27845: Kerawen Omnichannel Stocks
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
SQL injection vulnerability found in PrestaShop lekerawen_ocs before v.1.4.1 allow a remote attacker to gain privileges via the KerawenHelper::setCartOperationInfo, and KerawenHelper::resetCheckoutSessionData components.
Affected products
- Kerawen Omnichannel Stocks: before 1.4.1 (fixed in 1.4.1)
Published 2023-07-07. Last modified 2026-06-17.