A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7) allows remote unauthenticated attackers to execute arbitrary SQL queries via the fromController parameter in the popup controller. The parameter is passed unsanitized to SQL queries in classes/AdvancedPopup.php (getPopups() and updateVisits() functions).
Metrics
Affected Vendors & Products
References
History
Tue, 17 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Tue, 17 Feb 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Prestashop
Prestashop advanced Popup Creator |
|
| Vendors & Products |
Prestashop
Prestashop advanced Popup Creator |
Fri, 13 Feb 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7) allows remote unauthenticated attackers to execute arbitrary SQL queries via the fromController parameter in the popup controller. The parameter is passed unsanitized to SQL queries in classes/AdvancedPopup.php (getPopups() and updateVisits() functions). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-02-13T00:00:00.000Z
Updated: 2026-02-17T15:09:45.962Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-69633
Updated: 2026-02-17T15:07:52.748Z
Status : Awaiting Analysis
Published: 2026-02-13T22:16:09.650
Modified: 2026-02-18T17:52:44.520
Link: CVE-2025-69633
No data.