{"id":"CVE-2026-7848","title":"Alior Bank PrestaShop module \"raty\" for commercial partners is vulnerable to SQL Injection in the \"hookActionObjectProductUpdateBefore\", \"hookActionObjectCategoryUpdateBefore\", and \"hookActionObjectCategoryAddAfter\" hook methods","summary":"Alior Bank PrestaShop module \"raty\" for commercial partners is vulnerable to SQL Injection in the \"hookActionObjectProductUpdateBefore\", \"hookActionObjectCategoryUpdateBefore\", and \"hookActionObjectCategoryAddAfter\" hook methods. The mod…","severity":"high","cvss":8.6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N","cwe":["CWE-89"],"vendor":"Alior Bank","product":"raty","affected":["raty >= 8.0.0 < 8.1.11","raty >= 9.0.0 < 9.0.7"],"published":"2026-09-14","updated":"2026-09-18","sourceUpdated":"2026-09-18T17:49:08.457","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-7848","references":[{"url":"https://cert.pl/posts/2026/09/CVE-2026-7848","label":"cvd@cert.pl"},{"url":"https://www.aliorbank.pl/klienci-indywidualni/kredyty-i-pozyczki/kredyty-ratalne/informacje-dla-partnerow-handlowych.html","label":"cvd@cert.pl"}],"tags":["nvd","cve.org"],"epss":0.00263,"epssPercentile":0.18389,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-14T19:13:18.953048Z"},"cvssSource":"cna","ingestedAt":"2026-09-14T15:23:07.424Z","slug":"CVE-2026-7848","body":"## Overview\n\nAlior Bank PrestaShop module \"raty\" for commercial partners is vulnerable to SQL Injection in the \"hookActionObjectProductUpdateBefore\", \"hookActionObjectCategoryUpdateBefore\", and \"hookActionObjectCategoryAddAfter\" hook methods. The module inserts values of the POST parameters \"alior_product_promotion\",  \"alior_category_promotion\" and \"alior_category_enabled\" directly into SQL UPDATE queries without any sanitization or validation. An attacker with access to the product or category add/edit functionality in the PrestaShop backoffice can inject arbitrary SQL, potentially allowing unauthorized access to and modification of database contents. This issue was fixed in versions: 9.0.7 and 8.1.11\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":47.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}