peter bassill · operator
$ cve CVE-2022-31101 JSON

CVE-2022-31101 EXPLOIT

8.1
HIGH · CVSS 3.1 · EPSS 23.5% (pctl 98)

Patch early

A public exploit exists.

Description

prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds for this issue.

Scoring

CVSS8.1 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS23.49% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2022-06-27
Last modified2026-06-17

Affected (1)

VendorProduct
prestashopblockwishlist

Public exploits

SourceTitleDate
exploit-dbPrestashop blockwishlist module 2.1.0 - SQLi2022-08-09

References

→ the Explorer  ·  watch your stack  ·  NVD