Vulnerability CVE-2024-33267


Published: 2024-04-30

Description:
SQL Injection vulnerability in Hero hfheropayment v.1.2.5 and before allows an attacker to escalate privileges via the HfHeropaymentGatewayBackModuleFrontController::initContent() function.

 References:
https://www.heropay.eu/
https://security.friendsofpresta.org/modules/2024/04/29/hfheropayment.html

Copyright 2026, cxsecurity.com

 

Back to Top