First published: Wed Jan 20 2021(Updated: )
The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Prestashop Prestashop | =1.7.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3110 is a critical vulnerability in the store system of PrestaShop 1.7.7.0 that allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.
CVE-2021-3110 vulnerability has a severity rating of 9.8, which is considered critical.
PrestaShop 1.7.7.0 is the affected software version by CVE-2021-3110 vulnerability.
We do not provide guidance or support on exploiting vulnerabilities. It is recommended to report vulnerabilities to the software vendor or follow responsible disclosure practices.
To fix CVE-2021-3110 vulnerability, apply the latest security patch or update provided by PrestaShop.