CVE-2022-24956: SQL Injection
An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability allows a remote authenticated attacker to dump the underlying database.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-24956?
CVE-2022-24956 is an SQL injection vulnerability in Shopware B2B-Suite through version 4.4.1.
What is the severity of CVE-2022-24956?
CVE-2022-24956 has a severity rating of medium.
How does CVE-2022-24956 impact Shopware B2B-Suite?
CVE-2022-24956 allows remote authenticated attackers to execute arbitrary SQL commands in the search functionality of b2border and b2borderlist.
What versions of Shopware B2B-Suite are affected by CVE-2022-24956?
Shopware B2B-Suite versions 1.0.0 through 4.4.1 are affected by CVE-2022-24956.
How can I mitigate CVE-2022-24956?
Apply the latest security patch or update to a version that is not affected by CVE-2022-24956.