SQL Injection Vulnerability in Alior Bank's PrestaShop Module
CVE-2026-15600

8.6HIGH

Key Information:

Vendor

Alior Bank

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-15600?

The Alior Bank PrestaShop module 'raty' is susceptible to an SQL Injection vulnerability in the toggleCategoryPromotionAction method. This occurs because the module improperly handles input from the POST parameter 'status', directly inserting it into SQL UPDATE queries without adequate sanitization or validation. Consequently, an attacker with access to the back-office functionality to add or edit products or categories can exploit this flaw to execute arbitrary SQL commands, leading to unauthorized access to and potential alteration of sensitive database content.

Affected Version(s)

raty 8.1.9 < 8.1.12

raty 9.0.5 < 9.0.8

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

K. Winiarski <kwiniarski93@proton.me>
.