First published: Sun Mar 03 2024(Updated: )
SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MyPrestaModules Product Catalog (CSV, Excel) Import | <6.5.0 | |
Prestashop | <6.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25847 is considered a critical SQL Injection vulnerability that can lead to privilege escalation and unauthorized access to sensitive information.
To fix CVE-2024-25847, update the MyPrestaModules 'Product Catalog (CSV, Excel) Import' module to a version later than 6.5.0.
CVE-2024-25847 affects PrestaShop versions up to and including 6.5.0.
The exploit method for CVE-2024-25847 involves SQL Injection through the Send::__construct() and importProducts::_addDataToDb methods.
CVE-2024-25847 is specifically tied to the MyPrestaModules 'Product Catalog (CSV, Excel) Import' module for PrestaShop.