VYPR

updateproducts

by Prestashop

CVEs (2)

  • CVE-2023-39677Sep 20, 2023
    risk 0.06cvss epss 0.31

    MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.

  • CVE-2023-46349Nov 27, 2023
    risk 0.00cvss epss 0.01

    In the module "Product Catalog (CSV, Excel) Export/Update" (updateproducts) < 3.8.5 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `productsUpdateModel::getExportIds()` has sensitive SQL calls that can be executed with a trivial http call and…