Executive brief
Alior Bank's "raty" module for PrestaShop is a commercial installment loan integration plugin used by merchant partners to offer financing options at checkout. The module contains a SQL injection flaw that allows attackers with access to PrestaShop's administrative product or category management interface to inject malicious SQL commands, potentially reading or modifying sensitive e-commerce database records.
Technical details
The vulnerability is a SQL injection (CWE-89) in the toggleCategoryPromotionAction method of the Alior Bank raty PrestaShop module. The flaw occurs because the POST parameter "status" is inserted directly into SQL UPDATE queries without sanitization or parameterization. An attacker must have authenticated access to the PrestaShop backoffice with product or category management permissions. Exploitation allows arbitrary SQL execution, leading to unauthorized database access, modification, or potential information disclosure. The issue was patched in versions 8.1.12 and 9.0.8.
Affected products
- Alior Bank raty 8.1.9 to 8.1.12
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixed in versions 8.1.12 and 9.0.8