CVE-2021-37538
smartdatasoft smartblog Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2021-37538 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive controller, or the id_category parameter to the controllers/front/category.php category controller.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 11, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
smartblogBrowse smartdatasoft / smartblog | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALPrestaShop SmartBlog <4.0.6 - SQL InjectionCVSS 9.8
PrestaShop SmartBlog by SmartDataSoft < 4.0.6 is vulnerable to a SQL injection vulnerability in the blog archive functionality.
Impact
An attacker can gain unauthorized access to the database, extract sensitive information, modify data, or perform other malicious activities.
Remediation
Upgrade PrestaShop SmartBlog to version 4.0.6 or later to mitigate the SQL Injection vulnerability.
Source: ProjectDiscovery