Critical severity9.8NVD Advisory· Published Mar 8, 2024· Updated Jun 17, 2026
CVE-2024-25849
CVE-2024-25849
Description
In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer() and MakeOffers::addUserOffer()` .
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:prestatoolkit:make_an_offer\/offer_your_price:*:*:*:*:*:*:*:*Range: <=1.7.1
(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=1.7.1
- Range: <=1.7.1
Patches
Vulnerability mechanics
References
2- security.friendsofpresta.org/modules/2024/03/05/makeanoffer.htmlnvdPatchThird Party Advisory
- addons.prestashop.com/en/price-management/19507-make-an-offer.htmlnvdProduct
News mentions
0No linked articles in our index yet.