CVE-2024-28388: SQL Injection
Published Mar 14, 2024
·Updated
SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method.
Affected Software
3 affected components
SunnyToo stproductcomments<1.0.5
Prestashop PrestaShop<1.0.5
SunnyToo Product Comments Prestashop<1.0.6
Event History
Mar 14, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-28388?
CVE-2024-28388 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2024-28388?
To fix CVE-2024-28388, upgrade the SunnyToo stproductcomments module to version 1.0.6 or later.
3
What versions of PrestaShop are affected by CVE-2024-28388?
CVE-2024-28388 affects PrestaShop versions 1.0.5 and earlier.
4
What can an attacker achieve by exploiting CVE-2024-28388?
An attacker can escalate privileges and obtain sensitive information by exploiting CVE-2024-28388.
5
Who is the vendor for the affected SunnyToo stproductcomments module in CVE-2024-28388?
The vendor for the affected module is SunnyToo.