In the module mib < 1.6.1 from MyPresta.eu for PrestaShop...
Critical severity
Unreviewed
Published
Jan 19, 2024
to the GitHub Advisory Database
•
Updated Feb 3, 2024
Description
Published by the National Vulnerability Database
Jan 19, 2024
Published to the GitHub Advisory Database
Jan 19, 2024
Last updated
Feb 3, 2024
In the module mib < 1.6.1 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The methods
mib::getManufacturersByCategory()has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.References