Alior Bank PrestaShop 模块 "raty"(面向商业合作伙伴)在 方法中存在 SQL 注入漏洞。该模块将 POST 参数 "status" 的值直接插入到 SQL UPDATE 查询语句中,且未进行任何过滤或校验。因此,能够访问 PrestaShop 后台商品或分类添加/编辑功能的攻击者可以注入任意 SQL 语句,从而可能实现对数据库内容的不授权访问和修改。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Alior Bank | raty | 8.1.9 ~ 8.1.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet