CVE-2024-28392: Prestashop Abandoned Cart Reminder Pro
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method.
Affected products
- Prestashop Abandoned Cart Reminder Pro: up to and including 2.0.11
Published 2024-03-20. Last modified 2026-06-17.