advancedpopupcreator- PrestaShop module vulnerability (CVE-2025-69633)

Moduleadvancedpopupcreator

Score

9.8 Critical

Date publish

13-02-2026

Versiones afectadas

  • Versions from 1.1.26 up to but not including 1.2.7

Description

A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7) allows remote unauthenticated attackers to execute arbitrary SQL queries via the fromController parameter in the popup controller. The parameter is passed unsanitized to SQL queries in classes/AdvancedPopup.php (getPopups() and updateVisits() functions).

References

Metrics

cvssMetricV31
source134c704f-9b21-4f2e-91b3-4a467353bcc0
typeSecondary
version3.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
baseScore9.8
baseSeverityCRITICAL
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredNONE
userInteractionNONE
scopeUNCHANGED
confidentialityImpactHIGH
integrityImpactHIGH
availabilityImpactHIGH
exploitabilityScore3.9
impactScore5.9
Scroll al inicio