First published: Fri Mar 08 2024(Updated: )
In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection in affected versions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Team Ever Ultimate SEO | <=8.1.2 | |
Prestashop |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25848 has been rated as a critical vulnerability due to its potential for SQL injection by unauthenticated users.
To fix CVE-2024-25848, update the Ever Ultimate SEO module to version 8.1.3 or later.
The vulnerability CVE-2024-25848 affects all versions of Ever Ultimate SEO including and prior to 8.1.2.
Yes, CVE-2024-25848 can be exploited by unauthenticated guests due to the nature of the SQL injection vulnerability.
A temporary workaround for CVE-2024-25848 is to disable the Ever Ultimate SEO module until the update is applied to mitigate potential exploitation.