Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8v9p-7c45-26j2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive controller, or the id_category parameter to the controllers/front/category.php category controller.

Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive controller, or the id_category parameter to the controllers/front/category.php category controller.

EPSS

Процентиль: 100%
0.89404
Высокий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive controller, or the id_category parameter to the controllers/front/category.php category controller.

EPSS

Процентиль: 100%
0.89404
Высокий

Дефекты

CWE-89