PT-2024-26277 · Unknown · Create A Quote In Frontend + Backend Pro
Published
2024-06-24
·
Updated
2024-07-03
·
CVE-2024-34988
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Complete for Create a Quote in Frontend + Backend Pro module versions <= 1.0.51
Description
The issue allows attackers to view sensitive information and cause other impacts. This is achieved via methods such as
AskforaquotemodulcustomernewquoteModuleFrontController::run(), AskforaquotemoduladdproductnewquoteModuleFrontController::run(), AskforaquotemodulCouponcodeModuleFrontController::run(), AskforaquotemodulgetshippingcostModuleFrontController::run(), and AskforaquotemodulgetstateModuleFrontController::run().Recommendations
For versions <= 1.0.51, consider disabling the affected methods until a patch is available. Restrict access to the
Askforaquotemodul module to minimize the risk of exploitation. Avoid using the module's functionality in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Create A Quote In Frontend + Backend Pro