2 results (0.006 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

SunnyToo stblogsearch up to v1.0.0 was discovered to contain a SQL injection vulnerability via the StBlogSearchClass::prepareSearch component. Se descubrió que SunnyToo stblogsearch hasta v1.0.0 contiene una vulnerabilidad de inyección SQL a través del componente StBlogSearchClass::prepareSearch. • https://security.friendsofpresta.org/modules/2024/01/18/stblogsearch.html https://www.sunnytoo.com/product/panda-creative-responsive-prestashop-theme • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain sensitive information via StUrls::hookActionDispatcher and StUrls::getInstanceId methods. La vulnerabilidad de inyección SQL en SunnyToo, existente antes de la versión 1.1.13, permite a los atacantes escalar privilegios y obtener información confidencial a través de los métodos StUrls::hookActionDispatcher y StUrls::getInstanceId. • https://security.friendsofpresta.org/modules/2023/12/07/sturls.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •