SQL injection - Code In prestashop/prestashop
Description
SQL filter bypass leading to arbitrary write requests using "SQL Manager"
Impact
SQL filtering vulnerability, a BO user can write, update and delete in the database, even without having specific rights.
Patches
PrestaShop 8.0.4 and 1.7.8.9 will contain the patch.
Workarounds
no
References
no
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 8.0.4, 1.7.8.9 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5. 6.