SQL Injection Vulnerability in PrestaShop Module by PrestaShop
CVE-2024-28392
Currently unrated
What is CVE-2024-28392?
The PSCartAbandonmentPro module for PrestaShop contains a SQL injection vulnerability in versions up to 2.0.11. An attacker can exploit this flaw through the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method, which could allow unauthorized access and potential privilege escalation. It is crucial for users to apply the latest updates or patches provided by PrestaShop to mitigate this security risk.