CVE-2024-24310: SQL Injection
Published Feb 23, 2024
·Updated
In the module "Generate barcode on invoice / delivery slip" (ecgeneratebarcode) from Ether Creation <= 1.2.0 for PrestaShop, a guest can perform SQL injection.
Affected Software
3 affected components
Ether Creation ecgeneratebarcode<=1.2.0
Prestashop PrestaShop
Ethercreation Generate Barcode On Invoice \/ Delivery Slip Prestashop<=1.2.0
Event History
Feb 23, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24310?
CVE-2024-24310 has been assessed as a high-severity vulnerability due to the risk of SQL injection.
2
How do I fix CVE-2024-24310?
To fix CVE-2024-24310, update the ecgeneratebarcode module to a version greater than 1.2.0.
3
Which versions of ecgeneratebarcode are affected by CVE-2024-24310?
CVE-2024-24310 affects the ecgeneratebarcode module version 1.2.0 and all earlier versions.
4
Can guests exploit CVE-2024-24310?
Yes, CVE-2024-24310 allows guests to perform SQL injection attacks.
5
What impact does CVE-2024-24310 have on PrestaShop?
CVE-2024-24310 can potentially lead to unauthorized database access in PrestaShop installations using the affected module.