CVE-2022-24956
29.03.2022, 02:15
An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability allows a remote authenticated attacker to dump the underlying database.
Vendor | Product | Version |
---|---|---|
shopware | b2b_suite | 1.0.0 ≤ 𝑥 < 1.5.1 |
shopware | b2b_suite | 2.0.0 ≤ 𝑥 < 2.0.7 |
shopware | b2b_suite | 3.0.0 ≤ 𝑥 < 3.1.4 |
shopware | b2b_suite | 4.2.0 ≤ 𝑥 < 4.2.2 |
shopware | b2b_suite | 4.3.0 ≤ 𝑥 < 4.3.7 |
shopware | b2b_suite | 4.4.0 ≤ 𝑥 < 4.5.3 |
𝑥
= Vulnerable software versions