This advisory is a duplicate of GHSA-hrgx-p36p-89q4. This link is maintained to preserve external references.
PrestaShop 1.6.0.10 through 1.7.x before 1.7.8.2 allows remote attackers to execute arbitrary code, aka a "previously unknown vulnerability chain" related to SQL injection, as exploited in the wild in July 2022.
{
"cwe_ids": [
"CWE-89"
],
"github_reviewed": true,
"github_reviewed_at": "2022-08-05T18:57:58Z",
"nvd_published_at": "2022-07-22T22:15:00Z",
"severity": "CRITICAL"
}