SQL Injection vulnerability in the Innovadeluxe Quick Order module for PrestaShop before v.1.4.0, allows local attackers to execute arbitrary code via the getProducts() function in the productlist.php file.
https://security.friendsofpresta.org/modules/2023/12/12/idxquickorder.html