An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability allows a remote authenticated attacker to dump the underlying database.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-29708 An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability allows a remote authenticated attacker to dump the underlying database.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T04:29:01.513Z

Reserved: 2022-02-11T00:00:00

Link: CVE-2022-24956

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-03-29T02:15:07.413

Modified: 2024-11-21T06:51:27.467

Link: CVE-2022-24956

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses