CVE-2021-43789: Blind SQLi using Search filters in PrestaShop
Published Dec 7, 2021
·Updated
PrestaShop is an Open Source e-commerce web application. Versions of PrestaShop prior to 1.7.8.2 are vulnerable to blind SQL injection using search filters with orderBy and sortOrder parameters. The problem is fixed in version 1.7.8.2.
Affected Software
1 affected component
Prestashop PrestaShop>=1.7.5.0<1.7.8.2
Event History
Dec 7, 2021
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this PrestaShop vulnerability?
The vulnerability is identified as CVE-2021-43789.
2
What is the severity of CVE-2021-43789?
The severity of CVE-2021-43789 is critical with a CVSS score of 9.8.
3
How does CVE-2021-43789 affect PrestaShop?
Versions of PrestaShop prior to 1.7.8.2 are vulnerable to blind SQL injection using search filters.
4
How can I fix CVE-2021-43789?
To fix CVE-2021-43789, update your PrestaShop installation to version 1.7.8.2 or later.
5
Is there any additional information available about CVE-2021-43789?
Additional information about CVE-2021-43789 can be found on the PrestaShop GitHub page and the PrestaShop security advisories page.