---
id: CVE-2026-7848
title: "Alior Bank PrestaShop module \"raty\"\_for commercial partners is vulnerable to SQL Injection in the \"hookActionObjectProductUpdateBefore\", \"hookActionObjectCategoryUpdateBefore\", and \"hookActionObjectCategoryAddAfter\" hook methods"
summary: "Alior Bank PrestaShop module \"raty\"\_for commercial partners is vulnerable to SQL Injection in the \"hookActionObjectProductUpdateBefore\", \"hookActionObjectCategoryUpdateBefore\", and \"hookActionObjectCategoryAddAfter\" hook methods. The mod…"
severity: high
cvss: 8.6
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'
cwe:
  - CWE-89
vendor: Alior Bank
product: raty
affected:
  - raty >= 8.0.0 < 8.1.11
  - raty >= 9.0.0 < 9.0.7
published: '2026-09-14'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T17:49:08.457'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-7848'
references:
  - url: 'https://cert.pl/posts/2026/09/CVE-2026-7848'
    label: cvd@cert.pl
  - url: >-
      https://www.aliorbank.pl/klienci-indywidualni/kredyty-i-pozyczki/kredyty-ratalne/informacje-dla-partnerow-handlowych.html
    label: cvd@cert.pl
tags:
  - nvd
  - cve.org
epss: 0.00263
epssPercentile: 0.18424
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-14T19:13:18.953048Z'
cvssSource: cna
ingestedAt: '2026-09-14T15:23:07.424Z'
---

## Overview

Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the "hookActionObjectProductUpdateBefore", "hookActionObjectCategoryUpdateBefore", and "hookActionObjectCategoryAddAfter" hook methods. The module inserts values of the POST parameters "alior_product_promotion",  "alior_category_promotion" and "alior_category_enabled" directly into SQL UPDATE queries without any sanitization or validation. An attacker with access to the product or category add/edit functionality in the PrestaShop backoffice can inject arbitrary SQL, potentially allowing unauthorized access to and modification of database contents. This issue was fixed in versions: 9.0.7 and 8.1.11

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
