SQL injection in Wishlist - CVE-2022-31101
Published: July 26, 2022 / Updated: September 1, 2022
Vulnerability details
The vulnerability allows a remote user to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
Affected software
How to mitigate CVE-2022-31101
Links to Public Exploits and PoC-codes
- Exploit #8315 - Prestashop blockwishlist module 2.1.0 - SQLi (September 1, 2022)
- Exploit #8234 - CVE-2022-31101 (Exploit for PrestaShop bockwishlist module 2.1.0 SQLi (CVE-2022-31101)) (August 9, 2022)
- Exploit #8184 - blmvuln (Major Security Vulnerability on PrestaShop Websites - CVE-2022-31101) (July 26, 2022)
- Exploit #8183 - blm-vlun (Major Security Vulnerability on PrestaShop Websites - CVE-2022-31101) (July 26, 2022)