SQL Injection Vulnerability in Webbax Super Newsletter for PrestaShop
CVE-2024-33275

Currently unrated

Key Information:

Vendor

Webbax

Vendor
CVE Published:
30 April 2024

What is CVE-2024-33275?

An SQL injection vulnerability exists in the Webbax Super Newsletter for PrestaShop, affecting version 1.4.21 and earlier. This vulnerability allows a remote attacker to execute malicious SQL queries via the product_search.php component, which could lead to unauthorized privilege escalation through the Super Newsletter module. Organizations using affected versions are encouraged to apply security updates promptly to mitigate potential exploitation risks.

References

Timeline

  • Vulnerability published

.