CVE-2024-24308

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 9, 2024
Updated: Aug 19, 2024
CWE ID 89

Summary

CVE-2024-24308 is a newly disclosed SQL Injection vulnerability affecting the Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and older. This issue enables remote attackers to manipulate SQL queries in changeOrderCarrier.php, relayPoint.php, and shippingConfirmation.php, potentially leading to privileged escalation and data exfiltration. Successful exploitation can grant attackers unauthorized access to sensitive information, posing a significant risk to e-commerce websites using the vulnerable Prestashop versions. It is crucial for affected organizations to apply the necessary patches or updates as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share