Record summary

CVE-2024-36683 has a selected CVSS score of 7.3 (high); EIP currently links 1 Nuclei template.

Description

SQL injection vulnerability in the module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaShop allows attackers to obtain sensitive information and cause other impacts via the ProductsAlertAjaxProcessModuleFrontController::initContent method.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 25, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryCRITICALPrestaShop productsalert - SQL InjectionCVSS 9.8

In the module 'Products Alert' (productsalert) up to version 1.7.4 from Smart Modules for PrestaShop, a guest can perform SQL injection in affected versions.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized accessand data leakage.

Remediation

Apply the latest security patches and updates from the vendor to address this vulnerability.

WeaknessesCWE-89
Authorsmastercho
Template tagstime-based-sqlicvecve2024prestashopsqliproductsalertvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: html:"/productsalert"
FOFA: body="/productsalert"

Source: ProjectDiscovery

References

2