CVE-2024-25843: Prestashop Import/update Bulk Product

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQL injection in affected versions.

Affected products

  • Prestashop Import/update Bulk Product: before 1.1.29 (fixed in 1.1.29)

Published 2024-02-27. Last modified 2026-06-17.