Record summary

CVE-2022-22897 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 6, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALPrestaShop AP Pagebuilder <= 2.4.4 - SQL InjectionCVSS 9.8

A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized accessand data leakage.

Remediation

Upgrade PrestaShop Ap Pagebuilder to version 2.4.5 or later to mitigate this vulnerability.

WeaknessesCWE-89
Authorsmastercho
Template tagstime-based-sqlicvecve2022packetstormprestashopsqliunauthapollothemevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:apollotheme:ap_pagebuilder:*:*:*:*:*:prestashop:*:*
Shodan: http.component:"prestashop"

Source: ProjectDiscovery

References

3