Listen to this Post
The CVE-2024-36683 vulnerability affects the Smart Modules Products Alert (productsalert) module for PrestaShop up to version 1.7.4. This flaw belongs to the improper neutralization of special elements used in an SQL command class (CWE-89). It allows remote unauthenticated attackers to execute arbitrary SQL queries against the underlying database without requiring administrative privileges or user interaction.
The issue arises from unsafe handling of user-supplied input parameters within controller endpoints exposed by the module. Specifically, incoming HTTP parameters sent via GET or POST requests are concatenated directly into raw database query strings without proper sanitization, validation, or parameterized prepared statements. Because these inputs bypass validation checks, an attacker can supply malicious SQL payload syntax through web requests.
When processed by the database engine, the injected statements break out of the intended query context. Unauthenticated attackers can exploit this behavior to extract sensitive information including customer data, administrator hashes, and database configurations. In certain server configurations, this SQL injection can also be escalated to gain arbitrary file read/write permissions or execute command-line payloads.
DailyCVE Form:
Platform: PrestaShop
Version: <= 1.7.4
Vulnerability: SQL Injection
Severity: Critical 9.8
date: 2024-06-20
Prediction: Immediate Patch Available
What Undercode Say: Analytics
Analyzing this vulnerability highlights common secure coding oversights in third-party e-commerce plugins. Direct string concatenation inside database handlers bypasses ORM abstraction layers, creating entry points for full database compromise.
Identifying vulnerable module versions on target directory grep -rn "productsalert" /var/www/html/modules/productsalert/config.xml Intercepting GET parameters directed to the vulnerable controller curl -i -s "http://target-shop.com/modules/productsalert/ajax.php?id_product=1' AND (SELECT 1 FROM (SELECT(SLEEP(5)))a)-- "
-- Conceptual SQL Injection payload structure SELECT FROM `ps_product` WHERE id_product = 1' UNION SELECT 1, id_employee, passwd, email, 5 FROM ps_employee-- ;
How Exploit: (Educational Purposes!)
- Locate an instance running the `productsalert` module prior to version 1.7.5.
- Identify the vulnerable endpoint parameter that accepts user inputs without sanitization.
- Send a crafted HTTP request with a SQL payload designed to exfiltrate database contents or trigger time delays.
Protection:
Update the `productsalert` module to version 1.7.5 or higher.
Implement parameterized queries and prepared statements using PrestaShop’s DbQuery class.
Deploy a Web Application Firewall (WAF) to block common SQL injection patterns.
Impact:
Full exposure of backend database contents including customer PII and hashes.
Potential compromise of administrative accounts leading to full store takeover.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

