CVE-2022-24956

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
29/03/2022
Last modified:
05/04/2022

Description

An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability allows a remote authenticated attacker to dump the underlying database.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:* 1.0.0 (including) 1.5.1 (excluding)
cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:* 2.0.0 (including) 2.0.7 (excluding)
cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:* 3.0.0 (including) 3.1.4 (excluding)
cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:* 4.2.0 (including) 4.2.2 (excluding)
cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:* 4.3.0 (including) 4.3.7 (excluding)
cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:* 4.4.0 (including) 4.5.3 (excluding)