S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-3110 Scanner

CVE-2021-3110 scanner - SQL Injection (SQLi) vulnerability in PrestaShop

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-3110
9.8
CVSS

The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

PrestaShop is an open-source e-commerce platform that allows businesses to set up and manage their online stores easily. The platform has a sleek and user-friendly interface, making it accessible to even those with little to no technical background. Businesses can customize their store design and features to suit their brand and target audience. PrestaShop is a powerful tool for businesses looking to expand their online presence and reach a wider customer base.

CVE-2021-3110 is a vulnerability detected in PrestaShop 1.7.7.0. The vulnerability lies in the store system, particularly in the module=productcomments controller=CommentGrade id_products[] parameter, which allows time-based boolean SQL injection. Given that SQL injection is one of the most common web application vulnerabilities, this particular vulnerability could have severe consequences.

Exploiting this vulnerability could lead to unauthorized data access and manipulation, making confidential customer information vulnerable to theft. Attackers can use this vulnerability to execute arbitrary code, resulting in a complete compromise of the vulnerable system.

s4e.io is a platform that offers pro features for those interested in cybersecurity. By using this platform, users can quickly and easily learn about vulnerabilities in their digital assets. They can take proactive measures to secure their online presence while minimizing the risk of data breaches. By taking advantage of such platforms, businesses can ensure their reputation and customer trust remain intact.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take various precautions, including:

  • Update to the latest version of PrestaShop: The latest version of PrestaShop should fix this vulnerability.
  • Filter user inputs: Use input validation and filtering to prevent any malicious inputs.
  • Use a web application firewall: A web application firewall can help detect and block SQL injection attacks.
  • Regularly scan for vulnerabilities: Regular security auditing can detect vulnerabilities before attackers exploit them.
  • Implement access controls: Restricting access to sensitive information and functions can help prevent unauthorized access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-3110 scanner - SQL Injection (SQLi) vulnerability in PrestaShop | S4E