CVE-2024-25849

In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()` and `MakeOffers::addUserOffer()` .
Configurations

Configuration 1 (hide)

cpe:2.3:a:prestatoolkit:make_an_offer\/offer_your_price:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-03-08 02:15

Updated : 2025-05-05 15:06


NVD link : CVE-2024-25849

Mitre link : CVE-2024-25849

CVE.ORG link : CVE-2024-25849


JSON object : View

Products Affected

prestatoolkit

  • make_an_offer\/offer_your_price
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')