SQL Injection Vulnerability in Best-Kit Popup Module by PrestaShop
CVE-2024-28395
Currently unrated
What is CVE-2024-28395?
The Best-Kit Popup Module for PrestaShop is vulnerable to SQL injection, which allows remote attackers to manipulate database queries via the bestkit_popup.php component. This vulnerability can lead to unauthorized privilege escalation, potentially exposing sensitive data or compromising the integrity of the application. Users of affected versions are urged to review their security settings and apply necessary patches to mitigate potential risks.