Description
Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotionAction method. The module inserts value of the POST parameter "status" into SQL UPDATE queries without any sanitization or validation. An attacker with access to the product or category add/edit functionality in the PrestaShop backoffice can inject arbitrary SQL, potentially allowing unauthorized access to and modification of database contents.
Published: 2026-09-14
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Immediate Patch
AI Analysis

Impact

Alior Bank PrestaShop module "raty" contains a vulnerability in the toggleCategoryPromotionAction method that allows arbitrary SQL commands to be executed. The code inserts the raw value of the POST parameter "status" directly into an SQL UPDATE query without any sanitization or validation. The result is that a user with sufficient backoffice privileges can inject malicious SQL, potentially reading, modifying, or deleting database records that control product and category promotion data.

Affected Systems

The affected system is the Alior Bank "raty" module used by Alior Bank commercial partners. No specific module or PrestaShop version is provided, so all installations of this module that have not applied a fix may be vulnerable until a patch is deployed.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity vulnerability. The EPSS score is not available, so the probability of current exploitation cannot be quantified. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker needs access to the PrestaShop backoffice – typically local or internal – to manipulate the "status" parameter. If an attacker can compromise backoffice credentials or elevate privileges, they could execute arbitrary SQL and potentially gain unauthorized database access, leading to data tampering or disclosure.

Generated by OpenCVE AI on September 15, 2026 at 14:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official vendor patch that sanitizes the "status" parameter or replaces the query with a prepared statement.
  • Immediately restrict backoffice access to a minimal set of trusted administrators and ensure that the "status" field cannot be submitted by unauthenticated or low‑privilege users.
  • Conduct a code review or run static analysis to confirm that all user‑supplied parameters in the module are properly validated or parameterized before being used in database queries.

Generated by OpenCVE AI on September 15, 2026 at 14:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotionAction method. The module inserts value of the POST parameter "status" into SQL UPDATE queries without any sanitization or validation. An attacker with access to the product or category add/edit functionality in the PrestaShop backoffice can inject arbitrary SQL, potentially allowing unauthorized access to and modification of database contents.
Title SQL Injection in Alior Bank raty PrestaShop module
First Time appeared Alior Bank
Alior Bank raty
Weaknesses CWE-89
CPEs cpe:2.3:a:alior_bank:raty:*:*:*:*:*:*:*:*
Vendors & Products Alior Bank
Alior Bank raty
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-14T19:23:00.765Z

Reserved: 2026-07-13T14:16:31.529Z

Link: CVE-2026-15600

cve-icon Vulnrichment

Updated: 2026-09-14T19:15:21.385Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T15:17:04.393

Modified: 2026-09-18T17:49:08.457

Link: CVE-2026-15600

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:45:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')