PT-2024-27125 · Prestashop+1 · Isotope+1

Published

2024-06-24

·

Updated

2024-07-03

·

CVE-2024-36681

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PrestaShop module "Isotope" (pk isotope) versions <=1.7.3
Description The issue allows attackers to obtain sensitive information and cause other impacts via the pk isotope::saveData and pk isotope::removeData methods.
Recommendations For PrestaShop module "Isotope" (pk isotope) versions <=1.7.3, consider updating to a version higher than 1.7.3 to resolve the issue. As a temporary workaround, consider restricting access to the pk isotope::saveData and pk isotope::removeData methods until a patch is available.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-36681

Affected Products

Isotope
Prestashop