← Back

CVE-2022-24956

nvd nist
Published: Mar 29, 2022Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability allows a remote authenticated attacker to dump the underlying database.

Affected (6)

Products: Shopware: B2b Suite
1 product
B2b Suite
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Shopware
From 1.0.0 to 1.5.1
From 2.0.0 to 2.0.7
From 3.0.0 to 3.1.4
From 4.2.0 to 4.2.2
From 4.3.0 to 4.3.7
From 4.4.0 to 4.5.3

References (4)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
ExploitMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationThird Party Advisory

Timeline

No history available yet.