Multiple improper neutralization of SQL parameters in...
Critical severity
Unreviewed
Published
Oct 14, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Oct 14, 2023
Published to the GitHub Advisory Database
Oct 14, 2023
Last updated
Apr 4, 2024
Multiple improper neutralization of SQL parameters in module AfterMail (aftermailpresta) for PrestaShop, before version 2.2.1, allows remote attackers to perform SQL injection attacks via
id_customer
,id_conf
,id_product
andtoken
parameters in `aftermailajax.php via the 'id_product' parameter in hooks DisplayRightColumnProduct and DisplayProductButtons.References