CVE-2026-7848 | Alior Bank raty up to 8.1.10/9.0.6 sql injection

SecurityVulns

A vulnerability classified as problematic has been found in Alior Bank raty up to 8.1.10/9.0.6. The affected element is the function hookActionObjectProductUpdateBefore/hookActionObjectCategoryUpdateBefore/hookActionObjectCategoryAddAfter. Performing a manipulation of the argument alior_product_promotion/alior_category_promotion/alior_category_enabled results in sql injection.

This vulnerability was named CVE-2026-7848. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More