CVE-2022-31101

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
27/06/2022
Last modified:
09/12/2022

Description

prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds for this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:prestashop:blockwishlist:*:*:*:*:*:*:*:* 2.1.1 (excluding)