Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-31101

prestashop/blockwishlist is a prestashop extension which adds a block containing the customer’s wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds for this issue.

CVE
#sql#auth

SQL Injection

High

atomiix published GHSA-2jx3-5j9v-prpp

Jun 24, 2022

Package

composer prestashop/blockwishlist (Composer)

Affected versions

>=2.0.0

Patched versions

2.1.1

Description

Impact

An authenticated customer can perform SQL injection

Patches

Issue is fixed in 2.1.1

Severity

High

8.1

/ 10

CVSS base metrics

Attack vector

Network

Attack complexity

Low

Privileges required

Low

User interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

None

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CVE ID

CVE-2022-31101

Weaknesses

CWE-89

Credits

  • haiclover

Related news

Prestashop Blockwishlist 2.1.0 SQL Injection

Prestashop Blockwishlist module version 2.1.0 suffers from a remote SQL injection vulnerability.

GHSA-2jx3-5j9v-prpp: SQL Injection in BlockWishList

### Impact An authenticated customer can perform SQL injection ### Patches Issue is fixed in 2.1.1

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907