CVE-2024-36680 is a SQL injection vulnerability found in the Promokit.eu "Facebook" module (pkfacebook <=1.0.1) for PrestaShop, allowing unauthenticated guests to execute malicious SQL queries. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity and no user interaction, potentially leading to high confidentiality impact. While there are no public exploits in Metasploit, Nuclei, or ExploitDB, there is evidence of active exploitation, as indicated by media coverage reporting credit card theft. Community discussion and media coverage suggest moderate attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.