CVE-2022-31101: SQL Injection in prestashop/blockwishlist
Published Jun 27, 2022
·Updated
prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds for this issue.
Affected Software
1 affected component
Prestashop blockwishlist<2.1.1
Remediation
Event History
Jun 27, 2022
CVE Published
via MITRE·10:15 PM
Data Sourced
via MITRE·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-31101?
CVE-2022-31101 is a vulnerability in the Prestashop Blockwishlist extension that allows authenticated customers to perform SQL injection.
2
What is the severity of CVE-2022-31101?
CVE-2022-31101 has a severity rating of 8.8 (high).
3
What software is affected by CVE-2022-31101?
The Prestashop Blockwishlist extension versions up to and excluding 2.1.1 are affected by CVE-2022-31101.
4
How can I fix CVE-2022-31101?
To fix CVE-2022-31101, users are advised to upgrade to version 2.1.1 of the Prestashop Blockwishlist extension.
5
Are there any workarounds for CVE-2022-31101?
There are no known workarounds for CVE-2022-31101.