CVE-2021-36748
PrestaHome Blog for PrestaShop <1.7.8 - SQL Injection
Record summary
CVE-2021-36748 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHPrestaHome Blog for PrestaShop <1.7.8 - SQL InjectionCVSS 7.5
PrestaHome Blog for PrestaShop prior to version 1.7.8 is vulnerable to a SQL injection (blind) via the sb_category parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage.
Remediation
Upgrade to PrestaShop version 1.7.8 or later, or apply the provided patch to fix the SQL Injection vulnerability.
Source: ProjectDiscovery