Record summary

CVE-2022-31101 has a selected CVSS score of 8.1 (high); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.

Description

prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds for this issue.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List>= 2.0.0, < 2.1.1affected
GitHub Advisory2.0.0 to < 2.1.1 · Fixed in 2.1.1affected

Proofs of concept

2

Catalogued exploits

ExploitDBPrestashop blockwishlist module 2.1.0 - SQLiExploitDB exploitby Karthik UJNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubkarthikuj/CVE-2022-31101Repository PoCby karthikujStars: 25Not analyzed2 files

9.4 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHPrestashop Blockwishlist 2.1.0 SQL InjectionCVSS 8.1

Prestashop Blockwishlist module version 2.1.0 suffers from a remote authenticated SQL injection vulnerability.

Impact

Authenticated attackers can exploit SQL injection in the Blockwishlist module to extract sensitive database information including customer details, order data, and admin credentials from the PrestaShop database.

Remediation

Update Prestashop Blockwishlist module to a version newer than 2.1.0 that properly sanitizes user input and uses parameterized queries.

WeaknessesCWE-89
Authorsmastercho
Template tagspacketstormcvecve2022prestashopprestashop-modulesqliintrusive
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CPE: cpe:2.3:a:prestashop:blockwishlist:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5