CVE-2024-25843 Information
Feb 29, 2024
cve
Description
In the module \Import/Update Bulk Product from any Csv/Excel File Pro\ (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop a guest can perform SQL injection in affected versions.
Reference
https://addons.prestashop.com/en/data-import-export/20579-import-update-bulk-product-from-any-csv-excel-file-pro.html https://security.friendsofpresta.org/modules/2024/02/27/ba_importer.html
Share on: