Impact
The Alior Bank "raty" module for PrestaShop includes unsanitized POST parameters – "alior_product_promotion", "alior_category_promotion", and "alior_category_enabled" – in SQL UPDATE queries, creating a who can access the product or category add/edit functionality in the backoffice can inject arbitrary SQL, potentially exfiltrating or corrupting the shop’s database. This flaw is a CWE‑89 vulnerability and carries a CVSS score of 8.6, indicating a high‑severity risk that can lead to data loss or unauthorized modification.
Affected Systems
The issue affects the Alior Bank "raty" module distributed for PrestaShop. Versions earlier than 9.0.7 on the 9.x release line and earlier than 8.1.11 on the 8.x line remain vulnerable. The vendor’s fix is included in 9.0.7 and 8.1.11; any installation using older module releases should be upgraded.
Risk and Exploitability
With a CVSS score of 8.6 the flaw is severe, and although an EPSS score is not available and the vulnerability is not listed in KEV, the risk remains real. Exploitation requires the attacker to have access to the backoffice’s product or category editing forms, a privilege typically held by administrators or compromised admin accounts. Through these forms the attacker can execute arbitrary SQL, so limiting or disabling the vulnerable hooks until the patch is applied mitigates the risk.
OpenCVE Enrichment