CVE-2024-25847: SQL Injection
SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::construct() and importProducts::addDataToDb methods.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25847?
CVE-2024-25847 is considered a critical SQL Injection vulnerability that can lead to privilege escalation and unauthorized access to sensitive information.
How do I fix CVE-2024-25847?
To fix CVE-2024-25847, update the MyPrestaModules 'Product Catalog (CSV, Excel) Import' module to a version later than 6.5.0.
What versions of PrestaShop are affected by CVE-2024-25847?
CVE-2024-25847 affects PrestaShop versions up to and including 6.5.0.
What is the exploit method for CVE-2024-25847?
The exploit method for CVE-2024-25847 involves SQL Injection through the Send::__construct() and importProducts::_addDataToDb methods.
Can CVE-2024-25847 affect any other modules?
CVE-2024-25847 is specifically tied to the MyPrestaModules 'Product Catalog (CSV, Excel) Import' module for PrestaShop.