CVE-2024-25849

In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()` and `MakeOffers::addUserOffer()` .
Configurations

Configuration 1 (hide)

cpe:2.3:a:prestatoolkit:make_an_offer\/offer_your_price:*:*:*:*:*:*:*:*

History

05 May 2025, 15:06

Type Values Removed Values Added
First Time Prestatoolkit make An Offer\/offer Your Price
Prestatoolkit
References () https://addons.prestashop.com/en/price-management/19507-make-an-offer.html - () https://addons.prestashop.com/en/price-management/19507-make-an-offer.html - Product
References () https://security.friendsofpresta.org/modules/2024/03/05/makeanoffer.html - () https://security.friendsofpresta.org/modules/2024/03/05/makeanoffer.html - Patch, Third Party Advisory
CPE cpe:2.3:a:prestatoolkit:make_an_offer\/offer_your_price:*:*:*:*:*:*:*:*

21 Nov 2024, 09:01

Type Values Removed Values Added
References () https://addons.prestashop.com/en/price-management/19507-make-an-offer.html - () https://addons.prestashop.com/en/price-management/19507-make-an-offer.html -
References () https://security.friendsofpresta.org/modules/2024/03/05/makeanoffer.html - () https://security.friendsofpresta.org/modules/2024/03/05/makeanoffer.html -

01 Aug 2024, 13:47

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-89

08 Mar 2024, 14:02

Type Values Removed Values Added
Summary
  • (es) En el módulo "Hacer una oferta" (makeanoffer) &lt;= 1.7.1 de PrestaToolKit para PrestaShop, un invitado puede realizar una inyección SQL a través de MakeOffers::checkUserExistingOffer()` y `MakeOffers::addUserOffer()`.

08 Mar 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-08 02:15

Updated : 2025-05-05 15:06


NVD link : CVE-2024-25849

Mitre link : CVE-2024-25849

CVE.ORG link : CVE-2024-25849


JSON object : View

Products Affected

prestatoolkit

  • make_an_offer\/offer_your_price
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')