PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is fixed in version 1.7.8.3. There are no known workarounds.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-01-26T20:10:10
Updated: 2024-08-03T02:46:39.542Z
Reserved: 2021-11-16T00:00:00
Link: CVE-2022-21686
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-01-26T20:15:07.843
Modified: 2024-11-21T06:45:13.880
Link: CVE-2022-21686
Redhat
No data.