Vulnerability record · CVE-2023-46347 · published 25 October 2023
CVE-2023-46347: PrestaShop ndk_steppingpack module SQL injection via getPacks()
NNdkdesign · Ndk Steppingpack
The NDK Design "Step by Step products Pack" (ndk_steppingpack) module for PrestaShop, version 1.5.6 and earlier, passes unvalidated input into SQL queries in NdkSpack::getPacks(). An unauthenticated guest can trigger the injection with a simple HTTP request, exposing the store's database to full read and write compromise.
Description
In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. The method `NdkSpack::getPacks()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with unauthenticated network exploitation and a very high EPSS score make this an urgent patch target.
What it is
The NDK Design "Step by Step products Pack" (ndk_steppingpack) module for PrestaShop, version 1.5.6 and earlier, passes unvalidated input into SQL queries in NdkSpack::getPacks(). An unauthenticated guest can trigger the injection with a simple HTTP request, exposing the store's database to full read and write compromise.
Impact
An attacker can read, modify or delete arbitrary data in the PrestaShop database, including customer records and administrative credentials, and may pivot to code execution depending on database privileges.
Attack surface
Reachable over the network through a crafted HTTP request to the module's endpoint; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV and no public exploit reference is provided, but EPSS is 0.49885 (98.8th percentile), indicating a high likelihood of exploitation activity.
What to do
- Upgrade ndk_steppingpack to a version later than 1.5.6, or remove/disable the module if no fixed release is available.
- Apply a WAF rule blocking SQL metacharacters in requests to the module's endpoints.
- Restrict database account privileges used by PrestaShop to least privilege.
- Audit the PrestaShop database and logs for signs of tampering or injected content.
Detection
- Monitor web server and PrestaShop logs for requests to ndk_steppingpack endpoints containing SQL keywords, quotes or UNION/OR patterns.
- Enable and review database query logging for anomalous queries originating from the web application.
- Alert on unexpected changes to PrestaShop database tables or new administrative accounts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.friendsofpresta.org/modules/2023/10/24/ndk_steppingpack.html | Third Party Advisory |
| https://security.friendsofpresta.org/modules/2023/10/24/ndk_steppingpack.html | Third Party Advisory |
Track CVE-2023-46347 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-46347), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.