CVE-2014-2009: MPAY24 Project MPAY24

Medium severity, CVSS 5.0. EPSS: 7.4% chance of exploitation in the next 30 days.

The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path, and other sensitive information via a direct request to api/curllog.log.

Affected products

  • MPAY24 Project MPAY24: up to and including 1.5.1; version 1.4.0 only; version 1.4.1 only; version 1.4.2 only; version 1.4.3 only; version 1.4.4 only; …

Published 2014-09-12. Last modified 2026-06-17.