Vulnerability Description
The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Prestashop | Prestashop | 1.7.7.0 |
Related Weaknesses (CWE)
References
- https://medium.com/%40gondaliyajaimin797/cve-2021-3110-75a24943ca5e
- https://www.exploit-db.com/exploits/49410ExploitThird Party AdvisoryVDB Entry
- https://medium.com/%40gondaliyajaimin797/cve-2021-3110-75a24943ca5e
- https://www.exploit-db.com/exploits/49410ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2021-3110?
CVE-2021-3110 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.
How severe is CVE-2021-3110?
CVE-2021-3110 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-3110?
Check the references section above for vendor advisories and patch information. Affected products include: Prestashop Prestashop.