CVE-2022-24956
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
29/03/2022
Last modified:
05/04/2022
Description
An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability allows a remote authenticated attacker to dump the underlying database.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:* | 1.0.0 (including) | 1.5.1 (excluding) |
| cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:* | 2.0.0 (including) | 2.0.7 (excluding) |
| cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:* | 3.0.0 (including) | 3.1.4 (excluding) |
| cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:* | 4.2.0 (including) | 4.2.2 (excluding) |
| cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:* | 4.3.0 (including) | 4.3.7 (excluding) |
| cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:* | 4.4.0 (including) | 4.5.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



