Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-02171
HistoryJan 11, 2024 - 12:00 a.m.

PrestaShop SQL Injection Vulnerability (CNVD-2024-02171)

2024-01-1100:00:00
China National Vulnerability Database
www.cnvd.org.cn
15
prestashop
e-commerce
vulnerability
sql injection
payment methods
remote attacker
privileges
sensitive information

AI Score

7.5

Confidence

Low

EPSS

0.001

Percentile

27.3%

PrestaShop is an open source e-commerce solution from PrestaShop, Inc. in the United States. The solution provides a variety of payment methods, short message alerts and product image scaling and other features. PrestaShop suffers from a SQL injection vulnerability that stems from the application’s lack of validation of externally entered SQL statements. A remote attacker can exploit this vulnerability to elevate privileges and obtain sensitive information via the BaproductzoommagnifierZoomModuleFrontController::run() method.

AI Score

7.5

Confidence

Low

EPSS

0.001

Percentile

27.3%

Related for CNVD-2024-02171