VYPR

CSV Feeds PRO (csvfeeds)

by Prestashop

CVEs (2)

  • CVE-2023-46355Nov 27, 2023
    risk 0.00cvss epss 0.01

    In the module "CSV Feeds PRO" (csvfeeds) < 2.6.1 from Bl Modules for PrestaShop, a guest can download personal information without restriction. Due to too permissive access control which does not force administrator to use password on feeds, a guest can access exports from the…

  • CVE-2023-46356Oct 31, 2023
    risk 0.00cvss epss 0.01

    In the module "CSV Feeds PRO" (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop, a guest can perform SQL injection. The method `SearchApiCsv::getProducts()` has sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.