Description
The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Backup and Staging by WP Time Capsule Security Bypass (1.21.15)
phpMyAdmin Other Vulnerability (CVE-2007-1395)
Atlassian Jira Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2021-41306)
WordPress Plugin Insert or Embed Articulate Content into WordPress Directory Traversal (4.2999)