CVE-2018-8824: SQL Injection
Published May 10, 2018
·Updated
modules/bamegamenu/ajaxphpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute a SQL Injection through function calls in the code parameter.
Affected Software
2 affected components
Responsive Mega Menu Pro Project Responsive Mega Menu Pro Prestashop=1.0.32
Prestashop PrestaShop>=1.5.5.0<=1.7.2.5
Event History
May 10, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8824?
CVE-2018-8824 is rated as a high severity vulnerability due to the potential for remote SQL Injection attacks.
2
How do I fix CVE-2018-8824?
To fix CVE-2018-8824, update the Responsive Mega Menu Pro module to a version that patches this vulnerability.
3
What type of vulnerability is CVE-2018-8824?
CVE-2018-8824 is a SQL Injection vulnerability affecting the Responsive Mega Menu in PrestaShop.
4
Which versions of PrestaShop are affected by CVE-2018-8824?
CVE-2018-8824 affects PrestaShop versions from 1.5.5.0 through 1.7.2.5.
5
Who can exploit CVE-2018-8824?
Remote attackers can exploit CVE-2018-8824 to execute unauthorized SQL queries on the affected systems.