CVE-2024-25849
08.03.2024, 02:15
In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()` and `MakeOffers::addUserOffer()` .
Vendor | Product | Version |
---|---|---|
prestatoolkit | make_an_offer\/offer_your_price | 𝑥 ≤ 1.7.1 |
𝑥
= Vulnerable software versions
References