Lucene search

K
cveMitreCVE-2024-36678
HistoryJun 19, 2024 - 9:15 p.m.

CVE-2024-36678

2024-06-1921:15:57
CWE-89
mitre
web.nvd.nist.gov
29
cve-2024-36678
promokit.eu
prestashop
sql injection
ajax.php

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

Low

EPSS

0.001

Percentile

43.7%

In the module “Theme settings” (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.

Affected configurations

Nvd
Node
promokitpk_themesettingsRange1.8.8prestashop
VendorProductVersionCPE
promokitpk_themesettings*cpe:2.3:a:promokit:pk_themesettings:*:*:*:*:*:prestashop:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

Low

EPSS

0.001

Percentile

43.7%

Related for CVE-2024-36678