Record summary

CVE-2021-3110 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBPrestashop 1.7.7.0 - 'id_product' Time Based Blind SQL InjectionExploitDB exploitby Jaimin GondaliyaNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALPrestaShop 1.7.7.0 - SQL InjectionCVSS 9.8

PrestaShop 1.7.7.0 contains a SQL injection vulnerability via the store system. It allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Apply the latest security patch or upgrade to a non-vulnerable version of PrestaShop.

WeaknessesCWE-89
AuthorsJaimin Gondaliya, mastercho
Template tagstime-based-sqlicvecve2021sqliprestshopedbprestashopvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:prestashop:prestashop:1.7.7.0:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:prestashop:prestashop"

Source: ProjectDiscovery

References

4