CVE-2024-34988: SQL Injection
SQL injection vulnerability in the module "Complete for Create a Quote in Frontend + Backend Pro" (askforaquotemodul) <= 1.0.51 from Buy Addons for PrestaShop allows attackers to view sensitive information and cause other impacts via methods AskforaquotemodulcustomernewquoteModuleFrontController::run(), AskforaquotemoduladdproductnewquoteModuleFrontController::run(), AskforaquotemodulCouponcodeModuleFrontController::run(), AskforaquotemodulgetshippingcostModuleFrontController::run(), AskforaquotemodulgetstateModuleFrontController::run().
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34988?
CVE-2024-34988 has a high severity due to its potential to allow unauthorized access to sensitive information.
How do I fix CVE-2024-34988?
To fix CVE-2024-34988, update the 'Complete for Create a Quote in Frontend + Backend Pro' module to version 1.0.52 or later.
What causes CVE-2024-34988?
CVE-2024-34988 is caused by insufficient input validation for SQL queries in the affected module.
What impacts can CVE-2024-34988 have on my system?
CVE-2024-34988 can lead to data leakage and unauthorized access, potentially exposing sensitive customer information.
Is CVE-2024-34988 specific to certain versions of the software?
Yes, CVE-2024-34988 affects versions of the 'Complete for Create a Quote in Frontend + Backend Pro' module up to and including 1.0.51.