v1.6-v1.7 Newsletter Popup PRO with Voucher/Coupon code Module, V2.5.3

mtechie

Member
XNullUser
Joined
Sep 16, 2023
Messages
113
Reaction score
0
Points
16
Location
Turkey
NullCash
17
There is a security vulnerability in this module. Please do not use it.

The method NewsletterpopsendVerificationModuleFrontController::checkEmailSubscription() has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
WARNING : This exploit is actively used to deploy a webskimmer to massively steal credit cards.
This exploit uses a PrestaShop front controller and most attackers can conceal the module controller's path during the exploit, so you will never know within your conventional frontend logs that it exploits this vulnerability. You will only see "POST /" inside your conventional frontend logs. Activating the AuditEngine of mod_security (or similar) is the only way to get data to confirm this exploit.

For more info check this link please:
 
Top