First published: Wed Jun 19 2024(Updated: )
In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Promokit.eu Theme settings | <=1.8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-36678 is considered a high-severity vulnerability due to its potential for SQL injection attacks.
To fix CVE-2024-36678, upgrade the Theme settings module from Promokit.eu to a version higher than 1.8.8.
CVE-2024-36678 affects the Promokit.eu Theme settings module versions 1.8.8 and below for PrestaShop.
Yes, CVE-2024-36678 can be exploited remotely by a guest user through a simple HTTP call.
CVE-2024-36678 enables SQL injection attacks, which can compromise the database and extract sensitive information.