CVE-2022-22897
apollotheme ap_pagebuilder Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2022-22897 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 6, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ap_pagebuilderBrowse apollotheme / ap_pagebuilder | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALPrestaShop AP Pagebuilder <= 2.4.4 - SQL InjectionCVSS 9.8
A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized accessand data leakage.
Remediation
Upgrade PrestaShop Ap Pagebuilder to version 2.4.5 or later to mitigate this vulnerability.
Source: ProjectDiscovery