CVE-2023-27032Patch(idnovate / popup_module_\(on_entering\,_exit_popup\,_add_product\)_and_newsletter)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch idnovate popup_module_\(on_entering\,_exit_popup\,_add_product\)_and_newsletter systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups().

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • popup_module_\(on_entering\,_exit_popup\,_add_product\)_and_newsletter

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
popup_module_\(on_entering\,_exit_popup\,_add_product\)_and_newsletter

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-06: 1Active Exploitation · 2026-02-06: 1Patch / Workaround · 2026-02-06: 1Technical Details · 2026-02-06: 102-06
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2023-27032 : CRITICAL UNAUTHENTICATED SQL INJECTION ALERT 🚨 An unauthenticated SQL injection vulnerability has been disclosed in the advancedpopupcreator module for PrestaShop, exploitable via crafted HTTP requests to module frontend controllers and requiring no authentication or user interaction. Risk Severity: - Critical (CVSS 9.8, active exploitation, public exploits available) Impact: - Unauthenticated database compromise - Customer PII and payment data exfiltration - Administrative account takeover - Order and pricing manipulation - Ransomware staging and regulatory compliance violations (PCI-DSS, GDPR) Root Cause: - CWE-89 (SQL Injection). The AdvancedPopup::getPopups() method directly concatenates user-supplied parameters into SQL queries without input sanitization or prepared statements, allowing attacker-controlled SQL execution. Attackers can: - Send crafted requests to advancedpopupcreator frontend endpoints - Inject arbitrary SQL via id_shop and id_lang parameters - Extract customer, order, and administrator data - Modify database content and escalate to full admin control - Leverage database access for follow-on attacks and persistence Are You Affected? - Vulnerable: advancedpopupcreator versions 1.1.21 through 1.1.24 - Scope: Internet-facing PrestaShop production storefronts processing live orders Immediate Action Required: - Update: Upgrade advancedpopupcreator to version 1.1.25 or later immediately - Mitigation: Disable and uninstall the module if patching is delayed - Audit: Monitor module endpoint access, SQL error spikes, and anomalous database queries E-commerce platforms remain prime ransomware and data theft targets. Patch fast. 🛡️ #ostorlabCVE

    Post summary

    A critical unauthenticated SQL injection in PrestaShop's advancedpopupcreator module is actively exploited in the wild; a patch (v1.1.25+) is urgently required.

    00011151
    582 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appidnovatepopup_module_\(on_entering\,_exit_popup\,_add_product\)_and_newsletter-prestashop-

Explore more