SmartDataSoft SmartBlog for PrestaShop 4.06之前版本存在SQL注入漏洞 CVE-2021-37538

2022-09-07 SmartDataSoft SmartBlog PoC No

Description

SmartDataSoft SmartBlog for PrestaShop4.06之前版本存在SQL注入漏洞,该漏洞源于软件中的controllers/front/archive.php archivecontroller的day、month或year参数或controllers/front/category.php categorycontroller的id_category参数没有进行有效的验证或转义。攻击者可以执行任意SQL命令。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

Related Vulnerabilities