Record summary

CVE-2022-44727 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.

Description

The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ).

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 1, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryCRITICALPrestaShop lgcookieslaw - SQL InjectionCVSS 9.8

The EU Cookie Law GDPR (Banner + Blocker) PrestaShop module before 2.1.3 allows blind SQL injection via the __lglaw or lgcookieslaw cookie used to store user consent choices.

Impact

Successful exploitation allows unauthenticated attackers to read or modify the shop database, including customer PII and payment-related data.

Remediation

Upgrade the lgcookieslaw module to version 2.1.3 or later.

WeaknessesCWE-89
Authorsmastercho
Template tagscvecve2022prestashopprestashop-modulesqlitime-based-sqlilgcookieslawunauth
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: http.component:"Prestashop"
Shodan: http.component:"prestashop"

Source: ProjectDiscovery

References

4