Back

CRITICAL

Prestashop opartlimitquantity 1.4.5 and before is vulnerable to SQL Injection

Published Oct 31, 2023

Description

Prestashop opartlimitquantity 1.4.5 and before is vulnerable to SQL Injection. OpartlimitquantityAlertlimitModuleFrontController::displayAjaxPushAlertMessage()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Oct 31, 2023
Updated Sep 6, 2024
Reserved Jun 21, 2023

CISA Vulnrichment

Updated Sep 6, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner mitre
Published Oct 31, 2023
Updated Sep 6, 2024

GitHub

No data