{"id":"CVE-2026-7848","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-7848","summary":"Alior Bank PrestaShop module \"raty\" for commercial partners is vulnerable to SQL Injection in the \"hookActionObjectProductUpdateBefore\", \"hookActionObjectCategoryUpdateBefore\", and…","details":"Alior Bank PrestaShop module \"raty\" for commercial partners is vulnerable to SQL Injection in the \"hookActionObjectProductUpdateBefore\", \"hookActionObjectCategoryUpdateBefore\", and \"hookActionObjectCategoryAddAfter\" hook methods. The module inserts values of the POST parameters \"alior_product_promotion\",  \"alior_category_promotion\" and \"alior_category_enabled\" directly into SQL UPDATE queries without any sanitization or validation. An attacker with access to the product or category add/edit functionality in the PrestaShop backoffice can inject arbitrary SQL, potentially allowing unauthorized access to and modification of database contents. This issue was fixed in versions: 9.0.7 and 8.1.11","published":"2026-09-14T15:17:08.560","modified":"2026-09-14T15:17:08.560","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://cert.pl/posts/2026/09/CVE-2026-7848"},{"type":"WEB","url":"https://www.aliorbank.pl/klienci-indywidualni/kredyty-i-pozyczki/kredyty-ratalne/informacje-dla-partnerow-handlowych.html"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-14T15:17:08.560"}}