SQL Injection Vulnerability in Best-Kit Popup Module by PrestaShop
CVE-2024-28395

Currently unrated

Key Information:

Vendor

PrestaShop

Vendor
CVE Published:
20 March 2024

What is CVE-2024-28395?

The Best-Kit Popup Module for PrestaShop is vulnerable to SQL injection, which allows remote attackers to manipulate database queries via the bestkit_popup.php component. This vulnerability can lead to unauthorized privilege escalation, potentially exposing sensitive data or compromising the integrity of the application. Users of affected versions are urged to review their security settings and apply necessary patches to mitigate potential risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-28395 : SQL Injection Vulnerability in Best-Kit Popup Module by PrestaShop