PT-2022-3994 · Unknown · Prestashop
Atomiix
·
Published
2022-07-29
·
Updated
2025-10-11
·
CVE-2022-31181
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PrestaShop versions 1.6.0.10 through 1.7.8.7
Description
The issue is related to an SQL injection vulnerability in PrestaShop, an Open Source e-commerce platform. This vulnerability can be chained to call PHP's Eval function on attacker input, potentially allowing a remote attacker to execute arbitrary code. The problem is fixed in version 1.7.8.7.
Recommendations
For PrestaShop versions 1.6.0.10 through 1.7.8.7, upgrade to version 1.7.8.7 to resolve the issue.
For users unable to upgrade, delete the MySQL Smarty cache feature by removing the specified lines in the file
config/smarty.config.inc.php to mitigate the risk. Specifically, remove lines 43-46 for PrestaShop 1.7 or lines 40-43 for PrestaShop 1.6.Exploit
Fix
Eval Injection
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Prestashop