PT-2024-26284 · Channable · Channable

CVE-2024-34994

·

Published

2024-06-19

·

Updated

2024-07-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Channable for PrestaShop versions up to 3.2.1
Description The issue allows a guest to perform SQL injection via the ChannableFeedModuleFrontController::postProcess() function.
Recommendations For versions up to 3.2.1, consider disabling the ChannableFeedModuleFrontController::postProcess() function until a patch is available. Restrict access to the Channable module to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-34994

Affected Products

Channable