Record summary

CVE-2021-37538 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive controller, or the id_category parameter to the controllers/front/category.php category controller.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 11, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALPrestaShop SmartBlog <4.0.6 - SQL InjectionCVSS 9.8

PrestaShop SmartBlog by SmartDataSoft < 4.0.6 is vulnerable to a SQL injection vulnerability in the blog archive functionality.

Impact

An attacker can gain unauthorized access to the database, extract sensitive information, modify data, or perform other malicious activities.

Remediation

Upgrade PrestaShop SmartBlog to version 4.0.6 or later to mitigate the SQL Injection vulnerability.

WeaknessesCWE-89
Authorswhoever
Template tagscve2021cveprestashopsmartblogsqlismartdatasoftvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:smartdatasoft:smartblog:*:*:*:*:*:prestashop:*:*

Source: ProjectDiscovery

References

3