CVE-2024-24308
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-24308 is a newly disclosed SQL Injection vulnerability affecting the Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and older. This issue enables remote attackers to manipulate SQL queries in changeOrderCarrier.php, relayPoint.php, and shippingConfirmation.php, potentially leading to privileged escalation and data exfiltration. Successful exploitation can grant attackers unauthorized access to sensitive information, posing a significant risk to e-commerce websites using the vulnerable Prestashop versions. It is crucial for affected organizations to apply the necessary patches or updates as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.