PT-2022-27286 · Prestashop · Eu Cookie Law Gdpr
CVE-2022-44727
·
Published
2022-11-10
·
Updated
2025-05-01
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
EU Cookie Law GDPR (Banner + Blocker) module for PrestaShop version 2.1.3 and earlier
Description
The issue allows SQL Injection via a cookie, specifically
lgcookieslaw or lglaw. This can potentially lead to unauthorized access to sensitive data.Recommendations
For EU Cookie Law GDPR (Banner + Blocker) module for PrestaShop versions prior to 2.1.3, update to version 2.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the module until the update is applied. Avoid using the
lgcookieslaw or lglaw cookies in the affected module until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eu Cookie Law Gdpr