PT-2023-9164 · Prestashop+1 · Prestashop Buy Addons Baproductzoommagnifier Module+1
CVE-2023-50027
·
Publicado
2023-09-30
·
Atualizado
2024-01-11
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PrestaShop Buy Addons baproductzoommagnifier module versions 1.0.16 and before
Description
The issue is related to a lack of protection against SQL structure attacks in the BaproductzoommagnifierZoomModuleFrontController::run() method of the Best Zoom Magnifier Effect - BAZoom Magnifier web application for the open-source e-commerce platform PrestaShop. This can allow a remote attacker to escalate privileges and gain access to read, modify, or delete data. The
BaproductzoommagnifierZoomModuleFrontController::run() method is vulnerable to SQL injection attacks.Recommendations
For PrestaShop Buy Addons baproductzoommagnifier module versions 1.0.16 and before, consider disabling the
BaproductzoommagnifierZoomModuleFrontController::run() method until a patch is available to prevent potential SQL injection attacks.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Prestashop
Prestashop Buy Addons Baproductzoommagnifier Module