PT-2026-8039 · Prestashop · Advanced Popup Creator
CVE-2025-69633
·
Publicado
2026-02-13
·
Atualizado
2026-02-14
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PrestaShop Advanced Popup Creator module versions 1.1.26 through 1.2.6
Description
A SQL Injection issue exists in the Advanced Popup Creator module for PrestaShop. The issue is due to unsanitized data being passed to SQL queries within the
getPopups() and updateVisits() functions in the classes/AdvancedPopup.php file. Specifically, the fromController parameter is vulnerable. Attackers can remotely execute arbitrary SQL queries.Recommendations
Update to version 1.2.7 or later.
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Advanced Popup Creator