VYPR
Vendor

MyPrestaModules

Products
12
CVEs
12
Across products
23
Status
Private

Products

12

Recent CVEs

12
  • CVE-2024-25847CriMar 3, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and…

  • CVE-2023-46349CriNov 27, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "Product Catalog (CSV, Excel) Export/Update" (updateproducts) < 3.8.5 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `productsUpdateModel::getExportIds()` has sensitive SQL calls that can be executed with a trivial http call and…

  • CVE-2023-46357CriNov 22, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "Cross Selling in Modal Cart" (motivationsale) < 3.5.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `motivationsaleDataModel::getProductsByIds()` has sensitive SQL calls that can be executed with a trivial http call and…

  • CVE-2023-45387CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 5.0.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection via `exportProduct::_addDataToDb().`

  • CVE-2023-39675CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php.

  • CVE-2023-26858CriMar 31, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget component.

  • CVE-2024-25846CriFeb 27, 2024
    risk 0.59cvss 9.1epss 0.01

    In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php.

  • CVE-2023-40923HigNov 15, 2023
    risk 0.57cvss 8.8epss 0.01

    MyPrestaModules ordersexport before v5.0 was discovered to contain multiple SQL injection vulnerabilities at send.php via the key and save_setting parameters.

  • CVE-2023-39677HigSep 20, 2023
    risk 0.51cvss 7.5epss 0.31

    MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.

  • CVE-2024-28396HigMar 20, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component.

  • CVE-2023-46354HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.01

    In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of…

  • CVE-2023-46346HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control…