PT-2023-9164 · Prestashop+1 · Prestashop Buy Addons Baproductzoommagnifier Module+1

Published

2023-09-30

·

Updated

2024-01-11

·

CVE-2023-50027

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PrestaShop Buy Addons baproductzoommagnifier module versions 1.0.16 and before
Description The issue is related to a lack of protection against SQL structure attacks in the BaproductzoommagnifierZoomModuleFrontController::run() method of the Best Zoom Magnifier Effect - BAZoom Magnifier web application for the open-source e-commerce platform PrestaShop. This can allow a remote attacker to escalate privileges and gain access to read, modify, or delete data. The BaproductzoommagnifierZoomModuleFrontController::run() method is vulnerable to SQL injection attacks.
Recommendations For PrestaShop Buy Addons baproductzoommagnifier module versions 1.0.16 and before, consider disabling the BaproductzoommagnifierZoomModuleFrontController::run() method until a patch is available to prevent potential SQL injection attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-04302
CVE-2023-50027

Affected Products

Prestashop
Prestashop Buy Addons Baproductzoommagnifier Module