CVE-2024-28391: SQL Injection
SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProductAddToCart, getSearchProducts, and displayAjaxProductSku methods.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28391?
CVE-2024-28391 is classified as a high severity SQL injection vulnerability.
How do I fix CVE-2024-28391?
To fix CVE-2024-28391, update the FME Modules quickproducttable module to version 1.2.2 or later.
What impact does CVE-2024-28391 have on my PrestaShop installation?
CVE-2024-28391 allows a remote attacker to escalate privileges and access sensitive information in your PrestaShop installation.
Which versions of the FME Modules quickproducttable are affected by CVE-2024-28391?
CVE-2024-28391 affects FME Modules quickproducttable for PrestaShop versions 1.2.1 and earlier.
What actions can an attacker take by exploiting CVE-2024-28391?
By exploiting CVE-2024-28391, an attacker can execute unauthorized SQL queries and potentially compromise the application.