PT-2022-15724 · Apollotheme · Wp Page Builder

Published

2022-08-29

·

Updated

2023-03-03

·

CVE-2022-22897

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop
Description A SQL injection issue in the product all one img and image product parameters allows unauthenticated attackers to exfiltrate database data.
Recommendations For ApolloTheme AP PageBuilder component versions through 2.4.4, consider restricting access to the product all one img and image product parameters until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-22897

Affected Products

Wp Page Builder