Description
Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the "hookActionObjectProductUpdateBefore", "hookActionObjectCategoryUpdateBefore", and "hookActionObjectCategoryAddAfter" hook methods. The module inserts values of the POST parameters "alior_product_promotion",  "alior_category_promotion" and "alior_category_enabled" directly into SQL UPDATE queries without any sanitization or validation. An attacker with access to the product or category add/edit functionality in the PrestaShop backoffice can inject arbitrary SQL, potentially allowing unauthorized access to and modification of database contents. This issue was fixed in versions: 9.0.7 and 8.1.11
Published: 2026-09-14
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Database Compromise
Action: Patch Now
AI Analysis

Impact

The Alior Bank "raty" module for PrestaShop includes unsanitized POST parameters – "alior_product_promotion", "alior_category_promotion", and "alior_category_enabled" – in SQL UPDATE queries, creating a who can access the product or category add/edit functionality in the backoffice can inject arbitrary SQL, potentially exfiltrating or corrupting the shop’s database. This flaw is a CWE‑89 vulnerability and carries a CVSS score of 8.6, indicating a high‑severity risk that can lead to data loss or unauthorized modification.

Affected Systems

The issue affects the Alior Bank "raty" module distributed for PrestaShop. Versions earlier than 9.0.7 on the 9.x release line and earlier than 8.1.11 on the 8.x line remain vulnerable. The vendor’s fix is included in 9.0.7 and 8.1.11; any installation using older module releases should be upgraded.

Risk and Exploitability

With a CVSS score of 8.6 the flaw is severe, and although an EPSS score is not available and the vulnerability is not listed in KEV, the risk remains real. Exploitation requires the attacker to have access to the backoffice’s product or category editing forms, a privilege typically held by administrators or compromised admin accounts. Through these forms the attacker can execute arbitrary SQL, so limiting or disabling the vulnerable hooks until the patch is applied mitigates the risk.

Generated by OpenCVE AI on September 15, 2026 at 13:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Alior Bank raty module to8.1.11 for the 8.x branch) to apply the vendor patch that sanitizes inputs.
  • Restrict PrestaShop back‑office permissions so that only trusted administrators have product and category editing rights.
  • Until the patch is applied, temporarily disable or remove the "hookActionObjectProductUpdateBefore", "hookActionObjectCategoryUpdateBefore", and "hookActionObjectCategoryAddAfter" hooks or block the vulnerable POST parameters to block injection attempts.

Generated by OpenCVE AI on September 15, 2026 at 13:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the "hookActionObjectProductUpdateBefore", "hookActionObjectCategoryUpdateBefore", and "hookActionObjectCategoryAddAfter" hook methods. The module inserts values of the POST parameters "alior_product_promotion",  "alior_category_promotion" and "alior_category_enabled" directly into SQL UPDATE queries without any sanitization or validation. An attacker with access to the product or category add/edit functionality in the PrestaShop backoffice can inject arbitrary SQL, potentially allowing unauthorized access to and modification of database contents. This issue was fixed in versions: 9.0.7 and 8.1.11
Title SQL Injection in Alior Bank raty PrestaShop module
First Time appeared Alior Bank
Alior Bank raty
Weaknesses CWE-89
CPEs cpe:2.3:a:alior_bank:raty:*:*:*:*:*:*:*:*
Vendors & Products Alior Bank
Alior Bank raty
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-14T19:23:00.914Z

Reserved: 2026-05-05T10:36:59.919Z

Link: CVE-2026-7848

cve-icon Vulnrichment

Updated: 2026-09-14T19:15:24.431Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T15:17:08.560

Modified: 2026-09-18T17:49:08.457

Link: CVE-2026-7848

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T13:45:07Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')