
🚨 CVE-2023-27032 : CRITICAL UNAUTHENTICATED SQL INJECTION ALERT 🚨 An unauthenticated SQL injection vulnerability has been disclosed in the advancedpopupcreator module for PrestaShop, exploitable via crafted HTTP requests to module frontend controllers and requiring no authentication or user interaction. Risk Severity: - Critical (CVSS 9.8, active exploitation, public exploits available) Impact: - Unauthenticated database compromise - Customer PII and payment data exfiltration - Administrative account takeover - Order and pricing manipulation - Ransomware staging and regulatory compliance violations (PCI-DSS, GDPR) Root Cause: - CWE-89 (SQL Injection). The AdvancedPopup::getPopups() method directly concatenates user-supplied parameters into SQL queries without input sanitization or prepared statements, allowing attacker-controlled SQL execution. Attackers can: - Send crafted requests to advancedpopupcreator frontend endpoints - Inject arbitrary SQL via id_shop and id_lang parameters - Extract customer, order, and administrator data - Modify database content and escalate to full admin control - Leverage database access for follow-on attacks and persistence Are You Affected? - Vulnerable: advancedpopupcreator versions 1.1.21 through 1.1.24 - Scope: Internet-facing PrestaShop production storefronts processing live orders Immediate Action Required: - Update: Upgrade advancedpopupcreator to version 1.1.25 or later immediately - Mitigation: Disable and uninstall the module if patching is delayed - Audit: Monitor module endpoint access, SQL error spikes, and anomalous database queries E-commerce platforms remain prime ransomware and data theft targets. Patch fast. 🛡️ #ostorlabCVE
Post summary
A critical unauthenticated SQL injection in PrestaShop's advancedpopupcreator module is actively exploited in the wild; a patch (v1.1.25+) is urgently required.
