CVE Vulnerabilities

CVE-2024-25847

Improper Privilege Management

Published: Mar 03, 2024 | Modified: May 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SQL Injection vulnerability in MyPrestaModules Product Catalog (CSV, Excel) Import (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Product_catalog_(csv,_excel)_importMyprestamodules*6.5.0 (including)

Potential Mitigations

References