3 results (0.002 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

14 Mar 2024 — SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method. Vulnerabilidad de inyección SQL en el módulo stproductcomments de SunnyToo para PrestaShop v.1.0.5 y anteriores, permite a un atacante remoto escalar privilegios y obtener información confidencial a través del método StProductCommentClass::getListcomments. • https://security.friendsofpresta.org/modules/2024/03/12/stproductcomments.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

19 Jan 2024 — SunnyToo stblogsearch up to v1.0.0 was discovered to contain a SQL injection vulnerability via the StBlogSearchClass::prepareSearch component. Se descubrió que SunnyToo stblogsearch hasta v1.0.0 contiene una vulnerabilidad de inyección SQL a través del componente StBlogSearchClass::prepareSearch. • https://security.friendsofpresta.org/modules/2024/01/18/stblogsearch.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

14 Dec 2023 — SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain sensitive information via StUrls::hookActionDispatcher and StUrls::getInstanceId methods. La vulnerabilidad de inyección SQL en SunnyToo, existente antes de la versión 1.1.13, permite a los atacantes escalar privilegios y obtener información confidencial a través de los métodos StUrls::hookActionDispatcher y StUrls::getInstanceId. • https://security.friendsofpresta.org/modules/2023/12/07/sturls.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •