CVE-2024-25849 Information
Mar 09, 2024
cve
Description
In the module \Make an offer\ (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()andMakeOffers::addUserOffer()` .
Reference
https://addons.prestashop.com/en/price-management/19507-make-an-offer.html https://security.friendsofpresta.org/modules/2024/03/05/makeanoffer.html
Share on: