CVE-2024-24303 Information
Feb 08, 2024
cve
Description
SQL Injection vulnerability in HiPresta \Gift Wrapping Pro\ (hiadvancedgiftwrapping) module for PrestaShop before version 1.4.1 allows remote attackers to escalate privileges and obtain sensitive information via the HiAdvancedGiftWrappingGiftWrappingModuleFrontController::addGiftWrappingCartValue() method.
Reference
https://security.friendsofpresta.org/modules/2024/02/06/hiadvancedgiftwrapping.html
Share on: