CVE-2021-3110: SQL Injection
The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade idproducts[] parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-3110 vulnerability?
CVE-2021-3110 is a critical vulnerability in the store system of PrestaShop 1.7.7.0 that allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.
How severe is CVE-2021-3110 vulnerability?
CVE-2021-3110 vulnerability has a severity rating of 9.8, which is considered critical.
What software versions are affected by CVE-2021-3110 vulnerability?
PrestaShop 1.7.7.0 is the affected software version by CVE-2021-3110 vulnerability.
How can I exploit CVE-2021-3110 vulnerability?
We do not provide guidance or support on exploiting vulnerabilities. It is recommended to report vulnerabilities to the software vendor or follow responsible disclosure practices.
How can I fix the CVE-2021-3110 vulnerability?
To fix CVE-2021-3110 vulnerability, apply the latest security patch or update provided by PrestaShop.