SQL injection in PrestaShop - #VU144205
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to sql injection in back-office list filters when processing crafted filter names in back-office listings. A remote privileged user can send a crafted filter name to disclose sensitive information.
The issue was demonstrated with the most restricted built-in employee profile, indicating the permission system does not contain access to the exposed database content.