SQL Injection Vulnerability in Best-Kit Popup Module by PrestaShop
CVE-2024-28395

Currently unrated

Key Information:

Vendor
PrestaShop
Vendor
CVE Published:
20 March 2024

Summary

The Best-Kit Popup Module for PrestaShop is vulnerable to SQL injection, which allows remote attackers to manipulate database queries via the bestkit_popup.php component. This vulnerability can lead to unauthorized privilege escalation, potentially exposing sensitive data or compromising the integrity of the application. Users of affected versions are urged to review their security settings and apply necessary patches to mitigate potential risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.