CVE-2023-43986 | DM Concept Configurator up to 4.9.3 on PrestaShop getAttachmentByToken sql injection (EUVD-2023-48345)
A vulnerability described as critical has been identified in DM Concept Configurator up to 4.9.3 on PrestaShop. This vulnerability affects the function ConfiguratorAttachment::getAttachmentByToken. The manipulation results in sql injection.
This vulnerability is reported as CVE-2023-43986. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is recommended.