Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-36684


In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.


Published

2024-06-19T21:15:57.680

Last Modified

2024-11-21T09:22:32.807

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-89
  • Type: Secondary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application prestashop pk_customlinks ≤ 2.3 Yes

References