Vulnerability Details CVE-2024-24308
SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, relayPoint.php, and shippingConfirmation.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.2%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2024-24308
-
cpe:2.3:a:boostmyshop:boostmyshop:-
-
cpe:2.3:a:boostmyshop:boostmyshop:1.1.9