VYPR
Vendor

Blmodules

Products
2
CVEs
3
Across products
3
Status
Private

Products

2

Recent CVEs

3
  • CVE-2023-46356CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "CSV Feeds PRO" (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop, a guest can perform SQL injection. The method `SearchApiCsv::getProducts()` has sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.

  • CVE-2023-39643CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Bl Modules xmlfeeds before v3.9.8 was discovered to contain a SQL injection vulnerability via the component SearchApiXml::Xmlfeeds().

  • CVE-2023-46355MedNov 27, 2023
    risk 0.34cvss 5.3epss 0.01

    In the module "CSV Feeds PRO" (csvfeeds) < 2.6.1 from Bl Modules for PrestaShop, a guest can download personal information without restriction. Due to too permissive access control which does not force administrator to use password on feeds, a guest can access exports from the…