CVE-2024-25843 Information

Description

In the module \Import/Update Bulk Product from any Csv/Excel File Pro\ (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop a guest can perform SQL injection in affected versions.

Reference

https://addons.prestashop.com/en/data-import-export/20579-import-update-bulk-product-from-any-csv-excel-file-pro.html https://security.friendsofpresta.org/modules/2024/02/27/ba_importer.html

Share on: