PT-2022-3994 · Unknown · Prestashop

Atomiix

·

Published

2022-07-29

·

Updated

2025-10-11

·

CVE-2022-31181

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PrestaShop versions 1.6.0.10 through 1.7.8.7
Description The issue is related to an SQL injection vulnerability in PrestaShop, an Open Source e-commerce platform. This vulnerability can be chained to call PHP's Eval function on attacker input, potentially allowing a remote attacker to execute arbitrary code. The problem is fixed in version 1.7.8.7.
Recommendations For PrestaShop versions 1.6.0.10 through 1.7.8.7, upgrade to version 1.7.8.7 to resolve the issue. For users unable to upgrade, delete the MySQL Smarty cache feature by removing the specified lines in the file config/smarty.config.inc.php to mitigate the risk. Specifically, remove lines 43-46 for PrestaShop 1.7 or lines 40-43 for PrestaShop 1.6.

Exploit

Fix

Eval Injection

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2022-04827
CVE-2022-31181
GHSA-HRGX-P36P-89Q4

Affected Products

Prestashop