Vulnerability Description
A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7) allows remote unauthenticated attackers to execute arbitrary SQL queries via the fromController parameter in the popup controller. The parameter is passed unsanitized to SQL queries in classes/AdvancedPopup.php (getPopups() and updateVisits() functions).
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://addons.prestashop.com/en/pop-up-gamification/23773-popup-on-entry-exit-p
- https://labs.esokia.com/cve/cve-2025-69633/
FAQ
What is CVE-2025-69633?
CVE-2025-69633 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7) allows remote unauthenticated attackers to execut...
How severe is CVE-2025-69633?
CVE-2025-69633 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-69633?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.