← Back to CVE List

CVE-2024-25847

Published: 2024-03-03T09:15Z
Last Modified: 2024-11-21T09:01Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt