mirror of
https://github.com/0xMarcio/cve.git
synced 2025-06-19 17:30:12 +00:00
764 B
764 B
CVE-2024-25843
Description
In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQL injection in affected versions.
POC
Reference
- https://security.friendsofpresta.org/modules/2024/02/27/ba_importer.html
- https://security.friendsofpresta.org/modules/2024/02/27/ba_importer.html
Github
No PoCs found on GitHub currently.