CVE-2021-43789

Source
https://cve.org/CVERecord?id=CVE-2021-43789
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43789.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-43789
Aliases
Published
2021-12-07T17:15:10.027Z
Modified
2026-07-09T12:20:39.900227Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

PrestaShop is an Open Source e-commerce web application. Versions of PrestaShop prior to 1.7.8.2 are vulnerable to blind SQL injection using search filters with orderBy and sortOrder parameters. The problem is fixed in version 1.7.8.2.

References

Affected packages

Git / github.com/prestashop/prestashop

Affected ranges

Type
GIT
Repo
https://github.com/prestashop/prestashop
Events
Database specific
{
    "cpe": "cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.7.5.0"
        },
        {
            "fixed": "1.7.8.2"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43789.json"