PT-2021-21334 · Prestashop · Prestahome Blog

Published

2021-08-20

·

Updated

2021-08-30

·

CVE-2021-36748

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Prestahome Blog (aka ph simpleblog) module versions prior to 1.7.8 for Prestashop
Description A SQL Injection issue in the list controller of the Prestahome Blog module allows a remote attacker to extract data from the database via the sb category parameter.
Recommendations For Prestahome Blog (aka ph simpleblog) module versions prior to 1.7.8, update to version 1.7.8 or later to resolve the issue.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36748

Affected Products

Prestahome Blog