« Volver al listado

CVE-2022-24956

Estado: ModificadaMedia (6.5)—

An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability allows a remote authenticated attacker to dump the underlying database.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-24956",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-03-29T02:15:07.413",
  "references": [
    {
      "url": "https://syss.de",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-018.txt",
      "tags": [
        "Exploit",
        "Mitigation",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://syss.de",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-018.txt",
      "tags": [
        "Exploit",
        "Mitigation",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability allows a remote authenticated attacker to dump the underlying database."
    },
    {
      "lang": "es",
      "value": "Se ha detectado un problema en Shopware B2B-Suite versiones hasta 4.4.1. El parámetro sort-by de la funcionalidad search de b2border y b2borderlist permite la inyección de SQL. Las posibles técnicas son consultas ciegas basadas en booleanos, ciegas basadas en el tiempo y potencialmente apiladas. La vulnerabilidad permite que un atacante remoto autenticado descargue la base de datos subyacente"
    }
  ],
  "lastModified": "2026-06-17T04:32:51.380",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E9F3805-338D-4305-B590-85DC44545DA5",
              "versionEndExcluding": "1.5.1",
              "versionStartIncluding": "1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2104D347-DCAD-42CB-8B77-57BD4AA39068",
              "versionEndExcluding": "2.0.7",
              "versionStartIncluding": "2.0.0"
            },
            {
              "criteria": "cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6AD1B4E3-FDD3-40F8-ABCD-3272874A692F",
              "versionEndExcluding": "3.1.4",
              "versionStartIncluding": "3.0.0"
            },
            {
              "criteria": "cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5343AE8-CFC1-4990-9E9F-FF0B7C6FE181",
              "versionEndExcluding": "4.2.2",
              "versionStartIncluding": "4.2.0"
            },
            {
              "criteria": "cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8DFD8F89-BDEF-453C-8A17-8F8CB6E3CC44",
              "versionEndExcluding": "4.3.7",
              "versionStartIncluding": "4.3.0"
            },
            {
              "criteria": "cpe:2.3:a:shopware:b2b_suite:*:*:*:*:*:shopware:*:*",
              "vulnerable": true,
              "matchCriteriaId": "286AE9A1-94B0-4CAA-A129-F75F63A7CAE7",
              "versionEndExcluding": "4.5.3",
              "versionStartIncluding": "4.4.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}