CVE Vulnerabilities

CVE-2024-25847

Improper Privilege Management

Published: Mar 03, 2024 | Modified: May 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

SQL Injection vulnerability in MyPrestaModules Product Catalog (CSV, Excel) Import (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Product_catalog_(csv,_excel)_import Myprestamodules * 6.5.0 (including)

Potential Mitigations

References