CVE-2024-25849 Information

Description

In the module \Make an offer\ (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()andMakeOffers::addUserOffer()` .

Reference

https://addons.prestashop.com/en/price-management/19507-make-an-offer.html https://security.friendsofpresta.org/modules/2024/03/05/makeanoffer.html

Share on: