CVE-2024-28394
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/03/2024
Last modified:
15/04/2026
Description
An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistics, Custom Fields & Export module.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- https://addons.prestashop.com/en/customer-administration/28379-sales-reports-statistics-custom-fields-export.html
- https://security.friendsofpresta.org/modules/2024/03/14/reportsstatistics.html
- https://addons.prestashop.com/en/customer-administration/28379-sales-reports-statistics-custom-fields-export.html
- https://security.friendsofpresta.org/modules/2024/03/14/reportsstatistics.html



