CVE-2024-36684: SQL Injection
Published Jun 19, 2024
·Updated
In the module "Custom links" (pkcustomlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.
Affected Software
1 affected component
Prestashop Pk Customlinks<=2.3
Event History
Jun 19, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-36684?
CVE-2024-36684 has a high severity rating due to the potential for SQL injection attacks.
2
How do I fix CVE-2024-36684?
To fix CVE-2024-36684, update the Custom links (pk_customlinks) module to a version later than 2.3.
3
Who is affected by CVE-2024-36684?
All users of the Custom links (pk_customlinks) module version 2.3 and below for PrestaShop are affected by CVE-2024-36684.
4
What kind of attack is possible with CVE-2024-36684?
CVE-2024-36684 allows malicious users to perform SQL injection attacks that could lead to data breaches.
5
When was CVE-2024-36684 disclosed?
CVE-2024-36684 was disclosed in June 2024.