First published: Thu May 10 2018(Updated: )
modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute a SQL Injection through function calls in the code parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Responsive Mega Menu Pro | =1.0.32 | |
Prestashop | >=1.5.5.0<=1.7.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8824 is rated as a high severity vulnerability due to the potential for remote SQL Injection attacks.
To fix CVE-2018-8824, update the Responsive Mega Menu Pro module to a version that patches this vulnerability.
CVE-2018-8824 is a SQL Injection vulnerability affecting the Responsive Mega Menu in PrestaShop.
CVE-2018-8824 affects PrestaShop versions from 1.5.5.0 through 1.7.2.5.
Remote attackers can exploit CVE-2018-8824 to execute unauthorized SQL queries on the affected systems.