PrestaShop eval injection possible if shop vulnerable to SQL injection
Critical severity
GitHub Reviewed
Published
Jul 25, 2022
in
PrestaShop/PrestaShop
•
Updated Jan 27, 2023
Package
Affected versions
>= 1.6.0.10, < 1.7.8.7
Patched versions
1.7.8.7
Description
Published to the GitHub Advisory Database
Jul 29, 2022
Reviewed
Jul 29, 2022
Published by the National Vulnerability Database
Aug 1, 2022
Last updated
Jan 27, 2023
Impact
Eval injection possible if the shop is vulnerable to an SQL injection.
Patches
The problem is fixed in version 1.7.8.7
Workarounds
Delete the MySQL Smarty cache feature by removing these lines in the file
config/smarty.config.inc.php
lines 43-46 (PrestaShop 1.7) or 40-43 (PrestaShop 1.6):References