Description
A SQL injection vulnerability in the Boxtal (envoimoinscher) module for PrestaShop, after version 3.1.10, allows remote authenticated users to execute arbitrary SQL commands via the `key` GET parameter.
Remediation
References
Related Vulnerabilities
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-7572)
ClipBucket Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3717)
OpenSSL Other Vulnerability (CVE-2015-3194)
PrestaShop Incorrect Authorization Vulnerability (CVE-2020-5293)
WordPress Plugin DJ EmailPublish Cross-Site Scripting (1.7.2)