Record summary

CVE-2021-36748 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHPrestaHome Blog for PrestaShop <1.7.8 - SQL InjectionCVSS 7.5

PrestaHome Blog for PrestaShop prior to version 1.7.8 is vulnerable to a SQL injection (blind) via the sb_category parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage.

Remediation

Upgrade to PrestaShop version 1.7.8 or later, or apply the provided patch to fix the SQL Injection vulnerability.

WeaknessesCWE-89
Authorswhoever
Template tagscve2021cveprestashopprestahomesqlicmsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:prestahome:blog:*:*:*:*:*:prestashop:*:*

Source: ProjectDiscovery

References

4