cve/2024/CVE-2024-28391.md
2024-05-25 21:48:12 +02:00

765 B

CVE-2024-28391

Description

SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProductAddToCart, getSearchProducts, and displayAjaxProductSku methods.

POC

Reference

No PoCs from references.

Github