CVE-2021-37538: SQL Injection
Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive controller, or the idcategory parameter to the controllers/front/category.php category controller.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-37538?
CVE-2021-37538 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2021-37538?
To fix CVE-2021-37538, update SmartDataSoft SmartBlog to version 4.06 or later where this vulnerability has been addressed.
What types of attacks are possible with CVE-2021-37538?
CVE-2021-37538 allows attackers to perform SQL injection attacks through specific parameters, potentially compromising the database.
Who is affected by CVE-2021-37538?
CVE-2021-37538 affects users of SmartDataSoft SmartBlog for PrestaShop versions prior to 4.06.
Is authentication required to exploit CVE-2021-37538?
No, CVE-2021-37538 can be exploited by unauthenticated attackers, making it particularly dangerous.