CVE-2024-36678: SQL Injection
In the module "Theme settings" (pkthemesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36678?
CVE-2024-36678 is considered a high-severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2024-36678?
To fix CVE-2024-36678, upgrade the Theme settings module from Promokit.eu to a version higher than 1.8.8.
What software is affected by CVE-2024-36678?
CVE-2024-36678 affects the Promokit.eu Theme settings module versions 1.8.8 and below for PrestaShop.
Can CVE-2024-36678 be exploited remotely?
Yes, CVE-2024-36678 can be exploited remotely by a guest user through a simple HTTP call.
What kind of attack can CVE-2024-36678 enable?
CVE-2024-36678 enables SQL injection attacks, which can compromise the database and extract sensitive information.