CVE-2022-21686
PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is fixed in version 1.7.8.3. There are no known workarounds.
- Affected products
- Prestashop
- Prestashop
- ≤ 1.7.8.3
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 1.8% (77th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2022-01-26
CVE-2022-21686 at NVD
No indexed exploits for CVE-2022-21686 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-21686 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.