CVE-2021-3110
Prestashop 1.7.7.0 - 'id_product' Time Based Blind SQL Injection
Record summary
CVE-2021-3110 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBPrestashop 1.7.7.0 - 'id_product' Time Based Blind SQL InjectionExploitDB exploitby Jaimin GondaliyaNot analyzed1 file
Nuclei templates
1ProjectDiscoveryCRITICALPrestaShop 1.7.7.0 - SQL InjectionCVSS 9.8
PrestaShop 1.7.7.0 contains a SQL injection vulnerability via the store system. It allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Apply the latest security patch or upgrade to a non-vulnerable version of PrestaShop.
Source: ProjectDiscovery