CVE-2021-40814: SQL Injection
Published Sep 8, 2021
·Updated
The Customer Photo Gallery addon before 2.9.4 for PrestaShop is vulnerable to SQL injection.
Affected Software
1 affected component
MyPresta Customer Photo Gallery Prestashop<2.9.4
Event History
Sep 8, 2021
CVE Published
via MITRE·09:09 PM
Data Sourced
via MITRE·09:09 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-40814.
2
What is the severity of CVE-2021-40814?
The severity of CVE-2021-40814 is critical with a severity value of 9.8.
3
Which software versions are affected by CVE-2021-40814?
The Customer Photo Gallery addon before version 2.9.4 for PrestaShop is affected by CVE-2021-40814.
4
What is the impact of CVE-2021-40814?
CVE-2021-40814 allows for SQL injection attacks, which can lead to unauthorized access, data disclosure, and potential manipulation of the affected system's database.
5
How can I fix CVE-2021-40814?
To fix CVE-2021-40814, you should update the Customer Photo Gallery addon to version 2.9.4 or later.