Impact
Alior Bank PrestaShop module "raty" contains a vulnerability in the toggleCategoryPromotionAction method that allows arbitrary SQL commands to be executed. The code inserts the raw value of the POST parameter "status" directly into an SQL UPDATE query without any sanitization or validation. The result is that a user with sufficient backoffice privileges can inject malicious SQL, potentially reading, modifying, or deleting database records that control product and category promotion data.
Affected Systems
The affected system is the Alior Bank "raty" module used by Alior Bank commercial partners. No specific module or PrestaShop version is provided, so all installations of this module that have not applied a fix may be vulnerable until a patch is deployed.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity vulnerability. The EPSS score is not available, so the probability of current exploitation cannot be quantified. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker needs access to the PrestaShop backoffice – typically local or internal – to manipulate the "status" parameter. If an attacker can compromise backoffice credentials or elevate privileges, they could execute arbitrary SQL and potentially gain unauthorized database access, leading to data tampering or disclosure.
OpenCVE Enrichment