CVE-2024-25845: Cleanpresta Cd Custom Fields 4 Orders
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
In the module "CD Custom Fields 4 Orders" (cdcustomfields4orders) <= 1.0.0 from Cleanpresta.com for PrestaShop, a guest can perform SQL injection in affected versions.
Affected products
- Cleanpresta Cd Custom Fields 4 Orders: up to and including 1.0.0
Published 2024-03-08. Last modified 2026-06-17.