{"id":"CVE-2023-26861","details":"SQL injection vulnerability found in PrestaShop vivawallet v.1.7.10 and before allows a remote attacker to gain privileges via the vivawallet() module.","modified":"2026-08-12T03:51:31.874045909Z","published":"2023-07-11T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/26xxx/CVE-2023-26861.json"},"references":[{"type":"WEB","url":"https://addons.prestashop.com/fr/paiement/89363-viva-wallet-smart-checkout.html"},{"type":"WEB","url":"https://security.friendsofpresta.org/modules/2023/07/11/vivawallet.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/26xxx/CVE-2023-26861.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-26861"},{"type":"FIX","url":"https://github.com/VivaPayments/API/commit/c1169680508c6e144d3e102ebdb257612e4cd84a"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vivapayments/api","events":[{"introduced":"0"},{"fixed":"c1169680508c6e144d3e102ebdb257612e4cd84a"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-26861.json"}}],"schema_version":"1.9.0"}