In the module "Jms Setting" (jmssetting) from Joommasters...
Critical severity
Unreviewed
Published
Jan 19, 2024
to the GitHub Advisory Database
•
Updated Jun 17, 2025
Description
Published by the National Vulnerability Database
Jan 19, 2024
Published to the GitHub Advisory Database
Jan 19, 2024
Last updated
Jun 17, 2025
In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL injection in versions <= 1.1.0. The method
JmsSetting::getSecondImgs()has a sensitive SQL call that can be executed with a trivial http call and exploited to forge a blind SQL injection.References