CVE-2024-34989: SQL Injection
Published Jun 21, 2024
·Updated
In the module RSI PDF/HTML catalog evolution (prestapdf) <= 7.0.0 from RSI for PrestaShop, a guest can perform SQL injection via PrestaPDFProductListModuleFrontController::queryDb().'
Affected Software
2 affected components
RSI prestapdf<=7.0.0
Prestashop PrestaShop
Event History
Jun 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34989?
CVE-2024-34989 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2024-34989?
To fix CVE-2024-34989, upgrade the RSI PDF/HTML catalog evolution (prestapdf) module to version 7.0.1 or later.
3
Who is affected by CVE-2024-34989?
CVE-2024-34989 affects all users of RSI PDF/HTML catalog evolution (prestapdf) versions 7.0.0 and earlier on PrestaShop.
4
What type of vulnerability is CVE-2024-34989?
CVE-2024-34989 is an SQL injection vulnerability that allows unauthorized database access.
5
Can CVE-2024-34989 be exploited by unauthorized users?
Yes, CVE-2024-34989 can be exploited by guest users without authentication.