Store-opartCVEs & Vulnerabilities

7 CVEs affecting Store-opart products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

op\'art devis 2multi html block 1op\'art easy redirect 1op\'art limit quantity 1op\'art product faq 1op\'art save cart 1
CVE-2023-50061CRITICAL

PrestaShop Op'art Easy Redirect >= 1.3.8 and <= 1.3.12 is vulnerable to SQL Injection via Oparteasyredirect::hookActionDispatcher().

8 Feb 2024
9.8
CVSS
CVE-2023-48188CRITICAL

SQL injection vulnerability in PrestaShop opartdevis v.4.5.18 thru v.4.6.12 allows a remote attacker to execute arbitrary code via a crafted script to the getModuleTranslation function.

28 Nov 2023
9.8
CVSS
CVE-2023-36263CRITICAL

Prestashop opartlimitquantity 1.4.5 and before is vulnerable to SQL Injection. OpartlimitquantityAlertlimitModuleFrontController::displayAjaxPushAlertMessage()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

31 Oct 2023
9.8
CVSS
CVE-2023-30148MEDIUM

Multiple Stored Cross Site Scripting (XSS) vulnerabilities in Opart opartmultihtmlblock before version 2.0.12 and Opart multihtmlblock* version 1.0.0, allows remote authenticated users to inject arbitrary web script or HTML via the body_text or body_text_rude field in /sourcefiles/BlockhtmlClass.php and /sourcefiles/blockhtml.php.

14 Oct 2023
5.4
CVSS
CVE-2023-34576CRITICAL

SQL injection vulnerability in updatepos.php in PrestaShop opartfaq through 1.0.3 allows remote attackers to run arbitrary SQL commands via unspedified vector.

21 Sep 2023
9.8
CVSS
CVE-2023-34575CRITICAL

SQL injection vulnerability in PrestaShop opartsavecart through 2.0.7 allows remote attackers to run arbitrary SQL commands via OpartSaveCartDefaultModuleFrontController::initContent() and OpartSaveCartDefaultModuleFrontController::displayAjaxSendCartByEmail() methods.

21 Sep 2023
9.8
CVSS
CVE-2020-16194MEDIUM

An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploiting an IDOR on the delivery_address and invoice_address fields.

4 Feb 2021
5.3
CVSS
← PrevPage 1 / 1Next →