Vulnerabilities > CVE-2022-21686 - Code Injection vulnerability in Prestashop
PrestaShop is an Open Source e-commerce platform. Starting with version 184.108.40.206 and ending with version 220.127.116.11, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is fixed in version 18.104.22.168. There are no known workarounds.
Common Weakness Enumeration (CWE)
Common Attack Pattern Enumeration and Classification (CAPEC)
- Manipulating User-Controlled Variables This attack targets user controlled variables (DEBUG=1, PHP Globals, and So Forth). An attacker can override environment variables leveraging user-supplied, untrusted query variables directly used on the application server without any data sanitization. In extreme cases, the attacker can change variables controlling the business logic of the application. For instance, in languages like PHP, a number of poorly set default configurations may allow the user to override variables.