PT-2026-8039 · Prestashop · Advanced Popup Creator

CVE-2025-69633

·

Publicado

2026-02-13

·

Atualizado

2026-02-14

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PrestaShop Advanced Popup Creator module versions 1.1.26 through 1.2.6
Description A SQL Injection issue exists in the Advanced Popup Creator module for PrestaShop. The issue is due to unsanitized data being passed to SQL queries within the getPopups() and updateVisits() functions in the classes/AdvancedPopup.php file. Specifically, the fromController parameter is vulnerable. Attackers can remotely execute arbitrary SQL queries.
Recommendations Update to version 1.2.7 or later.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-69633

Produtos afetados

Advanced Popup Creator