← Back to browse · API

CVE-2022-31101

Severity
HIGH
CVSS
8.1
EPSS
0.22718
Risk score
40.35
CISA KEV
No
PoC
No
Published
2022-06-27
Modified
2025-04-22
First seen
2026-08-07
Aliases
EUVD-2022-5893, GHSA-2JX3-5J9V-PRPP
Products
PrestaShop:blockwishlist 2.0.0, < 2.1.1
Sources
euvd EUVD-2022-5893

Description

prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds for this issue.

References