CVE-2024-28391
14.03.2024, 04:15
SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProductAddToCart, getSearchProducts, and displayAjaxProductSku methods.Enginsight
Vendor | Product | Version |
---|---|---|
fmemodules | b2b_quick_order_form | 𝑥 < 1.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration