CVE-2024-36680: SQL Injection
In the module "Facebook" (pkfacebook) <=1.0.1 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The ajax script facebookConnect.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36680?
CVE-2024-36680 is considered a high severity vulnerability due to the potential for SQL injection risks.
How do I fix CVE-2024-36680?
To fix CVE-2024-36680, you should update the Promokit Facebook module to a version above 1.0.1.
Who is affected by CVE-2024-36680?
CVE-2024-36680 affects users of the Promokit pkfacebook module version 1.0.1 or earlier on PrestaShop.
What type of vulnerability is CVE-2024-36680?
CVE-2024-36680 is a SQL injection vulnerability that allows unauthorized SQL commands to be executed.
Can CVE-2024-36680 lead to data theft?
Yes, CVE-2024-36680 can potentially be exploited to steal sensitive data, including credit card information.