VYPR

Product Catalog \(csv\, Excel\) Import

by MyPrestaModules

CVEs (4)

  • CVE-2024-25847CriMar 3, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and…

  • CVE-2023-39675CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php.

  • CVE-2024-25846CriFeb 27, 2024
    risk 0.59cvss 9.1epss 0.01

    In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php.

  • CVE-2023-39677HigSep 20, 2023
    risk 0.51cvss 7.5epss 0.31

    MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.