CVE-2014-2008: MPAY24 Project MPAY24

High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.

SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to execute arbitrary SQL commands via the TID parameter.

Affected products

  • MPAY24 Project MPAY24: up to and including 1.5.1; version 1.4.0 only; version 1.4.1 only; version 1.4.2 only; version 1.4.3 only; version 1.4.4 only; …

Published 2014-09-12. Last modified 2026-06-17.