Skip to content

CVE-2014-2008

SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to execute arbitrary SQL commands via the TID parameter.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0392 (3.9%)
Percentile: 88.4%
EPSS: 2026-05-06

Affects

mpay24_project:mpay24

Technical description

SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to execute arbitrary SQL commands via the TID parameter.

Published: 9/12/2014, 2:55:06 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam