CVE-2022-31181 is a critical SQL injection vulnerability affecting PrestaShop versions 1.6.0.10 through 1.7.8.6. This flaw allows attackers to chain SQL injection with PHP's Eval function, enabling arbitrary code execution. With a CVSS score of 9.8, it poses a severe risk due to its network-based attack vector, low complexity, and complete compromise potential (confidentiality, integrity, availability). While not currently on the KEV catalog or actively exploited, exploit templates exist for tools like Nuclei, and its EPSS score indicates a high likelihood of exploitation. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.6.0.10, < 1.7.8.7CPE matchmatch criteria | cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.