Hackers are exploiting a flaw in a premium Facebook module for PrestaShop called pkfacebook to deploy a card skimmer on vulnerable e-commerce websites and steal users' payment credit card details.
See also: "Fake news" still exists on Facebook

PrestaShop is an open source e-commerce platform that allows individuals and businesses to create and manage online stores. As of 2024, it is used by approximately 300,000 online stores worldwide.
Promokit's pkfacebook plugin is a module that allows store visitors to log in using their Facebook accounts, leave comments under store pages, and communicate with support representatives using Messenger.
Promokit has over 12,500 sales on the Envato marketplace, but the Facebook module is only sold through the seller's website and no details on the number of sales are available.
The critical flaw, tracked as CVE-2024-36680, is an SQL injection in facebookConnect.php Ajax , which allows remote attackers to trigger SQL injection using HTTP requests.
Analysts at TouchWeb discovered the flaw on March 30, 2024, but Promokit.eu said the flaw had been fixed “a long time ago,” without providing any proof.
Earlier this week, Friends-of-Presta published a PoC for CVE-2024-36680 and warned that they are seeing active exploitation of the bug.
“This exploit is actively being used to develop a web skimmer for mass credit card theft,” says Friends-Of-Presta.
Unfortunately, the developers have not shared the latest version to confirm whether the flaw has been fixed.
See also: Spain bans election features on Facebook and Instagram

Friends -Of-Presta notes that all versions should be considered potentially affected and recommends the following mitigations:
- Upgrade to the latest version of pkfacebook, which disables multiple query executions, even if it does not protect against SQL injection, using the UNION.
- Make sure pSQL is used to avoid Stored XSS vulnerabilities, as it includes a strip_tags for added security.
- Modify the default “ps_” prefix to a longer one to improve security, although this measure is not foolproof against highly skilled attackers.
- Enable OWASP 942 rules in your Web Application Firewall (WAF).
NVD's entry for CVE-2024-36680 specifies that all versions 1.0.1 and older are vulnerable. However, the latest version of pkfacebook listed on the Promokit website is 1.0.0, so the patch availability status is unclear.
Hackers are closely watching for SQL injection flaws affecting web store platforms, as these can be used to gain administrator privileges, access or modify data on the site, extract database contents, and rewrite SMTP settings for email.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
About two years ago, PrestaShop issued an urgent warning and patch against attacks targeting modules vulnerable to SQL injection to achieve code execution on targeted websites.
See also: Facebook wants to use your posts to train AI
Credit card fraud is a serious crime that affects millions of people around the world. It involves the unauthorized use of someone else's credit card information to make purchases or withdraw money. This illegal activity not only causes financial losses to individuals and businesses, but also undermines confidence in the financial system.

To protect yourself from credit card fraud, it is important to regularly monitor your account activity for any unauthorized transactions and report them immediately. Additionally, using secure and trustworthy websites for online shopping and being vigilant about unsolicited requests for your card information can help protect against this type of theft.
Source: bleepingcomputer
