Showing 1 vulnerability on this page for newsletter_popup_pro

Signals CISA KEV Ransomware Nuclei
PrestaShop vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design for PrestaShop, a guest can perform SQL injection in affected versions. The method `NewsletterpopsendVerificationModuleFrontController::checkEmailSubscription()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

CWE-89Nov 15, 2023
CVSS9.8v3.1EPSS0.7%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX