First published: Fri Feb 23 2024(Updated: )
In the module "Generate barcode on invoice / delivery slip" (ecgeneratebarcode) from Ether Creation <= 1.2.0 for PrestaShop, a guest can perform SQL injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ecgeneratebarcode | <=1.2.0 | |
Prestashop | ||
Ethercreation Generate Barcode On Invoice / Delivery Slip Prestashop | <=1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24310 has been assessed as a high-severity vulnerability due to the risk of SQL injection.
To fix CVE-2024-24310, update the ecgeneratebarcode module to a version greater than 1.2.0.
CVE-2024-24310 affects the ecgeneratebarcode module version 1.2.0 and all earlier versions.
Yes, CVE-2024-24310 allows guests to perform SQL injection attacks.
CVE-2024-24310 can potentially lead to unauthorized database access in PrestaShop installations using the affected module.