{"id":"GHSA-6xxj-gcjq-wgf4","summary":"SQL injection in prestashop/prestashop","details":"### Impact\nBlind SQLi using Search filters with `orderBy` and `sortOrder` parameters\n\n### Patches\nThe problem is fixed in 1.7.8.2","aliases":["CVE-2021-43789"],"modified":"2026-05-07T05:01:16.129632472Z","published":"2021-12-07T21:23:17Z","database_specific":{"cwe_ids":["CWE-89"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-12-07T20:58:26Z","nvd_published_at":"2021-12-07T17:15:00Z"},"references":[{"type":"WEB","url":"https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-6xxj-gcjq-wgf4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43789"},{"type":"WEB","url":"https://github.com/PrestaShop/PrestaShop/issues/26623"},{"type":"WEB","url":"https://github.com/PrestaShop/PrestaShop/commit/6482b9ddc9dcebf7588dbfd616d2d635218408d6"},{"type":"WEB","url":"https://cwe.mitre.org/data/definitions/89.html"},{"type":"PACKAGE","url":"https://github.com/PrestaShop/PrestaShop"},{"type":"WEB","url":"https://github.com/PrestaShop/PrestaShop/releases/tag/1.7.8.2"}],"affected":[{"package":{"name":"prestashop/prestashop","ecosystem":"Packagist","purl":"pkg:composer/prestashop/prestashop"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.7.5.0"},{"fixed":"1.7.8.2"}]}],"versions":["1.7.5.0","1.7.5.1","1.7.5.2","1.7.6.0","1.7.6.0-beta.1","1.7.6.0-rc.1","1.7.6.0-rc.2","1.7.6.1","1.7.6.2","1.7.6.3","1.7.6.4","1.7.6.5","1.7.6.6","1.7.6.7","1.7.6.8","1.7.6.9","1.7.7.0","1.7.7.0-beta.1","1.7.7.0-beta.2","1.7.7.0-rc.1","1.7.7.1","1.7.7.2","1.7.7.3","1.7.7.4","1.7.7.5","1.7.7.6","1.7.7.7","1.7.7.8","1.7.8.0","1.7.8.0-beta.1","1.7.8.0-rc.1","1.7.8.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-6xxj-gcjq-wgf4/GHSA-6xxj-gcjq-wgf4.json","last_known_affected_version_range":"\u003c= 1.7.8.1"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}