CVE-2026-15600
nicheAuthenticated SQL Injection in Alior Bank 'raty' PrestaShop Module
The Alior Bank 'raty' installment module for PrestaShop (distributed to the bank's commercial partners) contains a SQL injection flaw in its toggleCategoryPromotionAction method, where the raw value of the POST parameter 'status' is inserted into SQL UPDATE queries without any sanitization or validation. An attacker who already has access to product or category add/edit functionality in the PrestaShop backoffice can submit a crafted 'status' value to inject and execute arbitrary SQL. Successful exploitation allows unauthorized reading and modification of the shop's database contents, including sensitive customer and order data, which is reflected in a CVSS 4.0 score of 8.6 (high). Affected sites are PrestaShop stores running this module, which is only offered to Alior Bank commercial partners — predominantly Polish merchants offering Alior installment payments. No public proof of concept exists and no exploitation in the wild has been reported; the CVE is not listed in CISA's KEV catalog.
What to do: Contact Alior Bank for a patched version of the 'raty' module and apply it as soon as one is released; if the installment feature is not needed, disable or remove the module in the meantime. Restrict PrestaShop backoffice permissions so that only fully trusted employees can add or edit products and categories, since the flaw requires that level of access. Review database and application logs for anomalous UPDATE queries or unexpected data changes originating from the module's promotion-toggle action.
| Alior Bank raty module for PrestaShop (module for commercial partners) | all versions (no affected version range or fixed version disclosed in the advisory) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotionAction method. The module inserts value of the POST parameter "status" into SQL UPDATE queries without any sanitization or validation. An attacker with access to the product or category add/edit functionality in the PrestaShop backoffice can inject arbitrary SQL, potentially allowing unauthorized access to and modification of database contents.
- Ecosystems
- E-commerce
- Weakness
- CWE-89
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.