SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProductAddToCart, getSearchProducts, and displayAjaxProductSku methods.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 10 Jun 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Fmemodules
Fmemodules b2b Quick Order Form
CPEs cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:* cpe:2.3:a:fmemodules:b2b_quick_order_form:*:*:*:*:*:prestashop:*:*
Vendors & Products Prestashop
Prestashop prestashop
Fmemodules
Fmemodules b2b Quick Order Form

Tue, 10 Jun 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Prestashop
Prestashop prestashop
CPEs cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*
Vendors & Products Prestashop
Prestashop prestashop

Thu, 10 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Fme Modules
Fme Modules quickproducttable Module For Pestashop
CPEs cpe:2.3:a:fme_modules:quickproducttable_module_for_pestashop:*:*:*:*:*:*:*:*
Vendors & Products Fme Modules
Fme Modules quickproducttable Module For Pestashop
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-04-10T20:32:56.016Z

Reserved: 2024-03-08T00:00:00.000Z

Link: CVE-2024-28391

cve-icon Vulnrichment

Updated: 2024-08-02T00:56:56.434Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-14T04:15:09.697

Modified: 2025-06-10T16:25:58.220

Link: CVE-2024-28391

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.