CVE-2023-39640 | UpLight cookiebanner up to 1.5.0 on PrestaShop getHookModuleExecList sql injection
A vulnerability, which was classified as critical, was found in UpLight cookiebanner up to 1.5.0 on PrestaShop. Affected is the function Hook::getHookModuleExecList. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2023-39640. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.