← volver
CVE-2022-21686criticalCWE-94

Server Side Twig Template Injection in PrestaShop

28Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 9epss 1.8%
probabilidad de explotación
1.8%top 24% de las CVE
explotación observada
noninguna fuente lo reporta
PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is fixed in version 1.7.8.3. There are no known workarounds.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Productos afectados
PrestaShop · PrestaShop