Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotionAction method. The module inserts value of the POST parameter "status" into SQL UPDATE queries without any sanitization or validation. An attacker with access to the product or category add/edit functionality in the PrestaShop backoffice can inject arbitrary SQL, potentially allowing unauthorized access to and modification of database contents. | |
| Title | SQL Injection in Alior Bank raty PrestaShop module | |
| First Time appeared |
Alior Bank
Alior Bank raty |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:alior_bank:raty:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Alior Bank
Alior Bank raty |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-09-14T19:23:00.765Z
Reserved: 2026-07-13T14:16:31.529Z
Link: CVE-2026-15600
Updated: 2026-09-14T19:15:21.385Z
Status : Received
Published: 2026-09-14T15:17:04.393
Modified: 2026-09-14T20:16:38.417
Link: CVE-2026-15600
No data.
OpenCVE Enrichment
No data.