SQL filter bypass leading to arbitrary write requests using "SQL Manager"
Critical severity
GitHub Reviewed
Published
Apr 25, 2023
in
PrestaShop/PrestaShop
•
Updated Nov 10, 2023
Package
Affected versions
>= 8.0.0, < 8.0.4
< 1.7.8.9
Patched versions
8.0.4
1.7.8.9
Description
Published by the National Vulnerability Database
Apr 25, 2023
Published to the GitHub Advisory Database
Apr 25, 2023
Reviewed
Apr 25, 2023
Last updated
Nov 10, 2023
Impact
SQL filtering vulnerability, a BO user can write, update and delete in the database, even without having specific rights.
Patches
PrestaShop 8.0.4 and 1.7.8.9 will contain the patch.
Workarounds
no
References
no
References