CVE-2024-36681: SQL Injection
Published Jun 24, 2024
·Updated
SQL Injection vulnerability in the module "Isotope" (pkisotope) <=1.7.3 from Promokit.eu for PrestaShop allows attackers to obtain sensitive information and cause other impacts via pkisotope::saveData and pkisotope::removeData methods.
Affected Software
1 affected component
Promokit Isotope<=1.7.3
Event History
Jun 24, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-36681?
CVE-2024-36681 is classified as a high-severity SQL Injection vulnerability.
2
How do I fix CVE-2024-36681?
To fix CVE-2024-36681, update the Promokit Isotope module to a version later than 1.7.3.
3
What impact can CVE-2024-36681 have on my system?
CVE-2024-36681 can allow attackers to obtain sensitive information and potentially compromise the integrity of the system.
4
Which versions of the Isotope module are affected by CVE-2024-36681?
CVE-2024-36681 affects versions of the Isotope module up to and including 1.7.3.
5
Where can I find more information about CVE-2024-36681?
More information about CVE-2024-36681 can be found in security advisories related to the Promokit Isotope module.