PT-2023-9164 · Prestashop+1 · Prestashop Buy Addons Baproductzoommagnifier Module+1

CVE-2023-50027

·

Publicado

2023-09-30

·

Atualizado

2024-01-11

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PrestaShop Buy Addons baproductzoommagnifier module versions 1.0.16 and before
Description The issue is related to a lack of protection against SQL structure attacks in the BaproductzoommagnifierZoomModuleFrontController::run() method of the Best Zoom Magnifier Effect - BAZoom Magnifier web application for the open-source e-commerce platform PrestaShop. This can allow a remote attacker to escalate privileges and gain access to read, modify, or delete data. The BaproductzoommagnifierZoomModuleFrontController::run() method is vulnerable to SQL injection attacks.
Recommendations For PrestaShop Buy Addons baproductzoommagnifier module versions 1.0.16 and before, consider disabling the BaproductzoommagnifierZoomModuleFrontController::run() method until a patch is available to prevent potential SQL injection attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-04302
CVE-2023-50027

Produtos afetados

Prestashop
Prestashop Buy Addons Baproductzoommagnifier Module