← Back

Chronopost

chronopost

1 CVE • 1 product

Products (1)

Click to collapse
Toggle
Chronopost
chronopost

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Chronopost
1Chronopost
Jun 17, 2026
Nov 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In the module "Chronopost Official" (chronopost) for PrestaShop, a guest can perform SQL injection. The script PHP `cancelSkybill.php` own a sensitive SQL calls that can be executed with a trivial http call and exploited...Show more
In the module "Chronopost Official" (chronopost) for PrestaShop, a guest can perform SQL injection. The script PHP `cancelSkybill.php` own a sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.Show less