Vulnerability Description
In the module "Generate barcode on invoice / delivery slip" (ecgeneratebarcode) from Ether Creation <= 1.2.0 for PrestaShop, a guest can perform SQL injection.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ethercreation | Generate Barcode On Invoice \/ Delivery Slip | <= 1.2.0 |
Related Weaknesses (CWE)
References
- https://addons.prestashop.com/en/preparation-shipping/24123-generate-barcode-on-Third Party Advisory
- https://security.friendsofpresta.org/modules/2024/02/20/ecgeneratebarcode.htmlProduct
- https://addons.prestashop.com/en/preparation-shipping/24123-generate-barcode-on-Third Party Advisory
- https://security.friendsofpresta.org/modules/2024/02/20/ecgeneratebarcode.htmlProduct
FAQ
What is CVE-2024-24310?
CVE-2024-24310 is a vulnerability with a CVSS score of 8.8 (HIGH). In the module "Generate barcode on invoice / delivery slip" (ecgeneratebarcode) from Ether Creation <= 1.2.0 for PrestaShop, a guest can perform SQL injection.
How severe is CVE-2024-24310?
CVE-2024-24310 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-24310?
Check the references section above for vendor advisories and patch information. Affected products include: Ethercreation Generate Barcode On Invoice \/ Delivery Slip.