cve/2024/CVE-2024-25849.md
2024-05-25 21:48:12 +02:00

658 B

CVE-2024-25849

Description

In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()andMakeOffers::addUserOffer()` .

POC

Reference

No PoCs from references.

Github