{"id":41163,"date":"2022-07-27T06:45:00","date_gmt":"2022-07-27T06:45:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/41163"},"modified":"2022-07-27T06:45:00","modified_gmt":"2022-07-27T06:45:00","slug":"retail-software-firm-prestashop-warns-users-about-sql-injection-attacks","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=41163","title":{"rendered":"Retail software firm PrestaShop warns users about SQL injection attacks"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/07\/retail-software-firm-prestashop-warns-users-about-sql-injection-attacks.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p><a href=\"https:\/\/build.prestashop.com\/news\/major-security-vulnerability-on-prestashop-websites\/\">PrestaShop<\/a>, a developer of open source e-commerce software used by hundreds of thousands of small, independent retailers as the foundations of their online presence, has warned of a serious vulnerability that, left unaddressed, would allow attackers to achieve arbitrary code execution and steal customer card data.<\/p>\n<p><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022-36408\">Tracked as CVE-2022-36408<\/a>, the vulnerability first came to light when PrestaShop was made aware that cyber criminals were exploiting \u201ca combination of known and unknown security vulnerabilities\u201d to inject malicious code into websites relying on the platform.<\/p>\n<p>In the course of this investigation, its team found a previously unknown vulnerability chain affecting \u2013 to the best of the firm\u2019s knowledge \u2013 shops built on versions 1.6.8.10 or higher that are vulnerable to SQL injection attacks. Note that versions 1.7.8.2 and above are not vulnerable unless running modules or custom code that itself includes a <a href=\"https:\/\/www.techtarget.com\/searchsoftwarequality\/definition\/SQL-injection\">SQL injection vulnerability<\/a>.<\/p>\n<p>\u201cThe attack requires the shop to be vulnerable to SQL injection exploits. To the best of our knowledge, the latest version of PrestaShop and its modules are free from these vulnerabilities. We believe attackers are targeting shops using outdated software or modules, vulnerable third-party modules, or a yet-to-be-discovered vulnerability,\u201d said PrestaShop in an advisory published on 22 July.<\/p>\n<p>Despite this uncertainty, its investigations have established a recurring attack pattern. First, the attacker submits a POST request to the vulnerable endpoint. They then receive a GET request to the homepage without parameters, resulting in the creation of a PHP file at the root of the shop\u2019s directory. From there, they can submit a GET request to that new file, allowing them to execute arbitrary code.<\/p>\n<p>This accomplished, the attacker can then inject a fake payment form on the victim\u2019s checkout page, enabling them to steal customer credit card data.<\/p>\n<blockquote class=\"main-article-pullquote\">\n<p><figure> \u201cEvidence showing how the PrestaShop platform is being exploited by hackers is a stark reminder that platforms need to be updated regularly to ensure you have the latest security benefits\u201d <\/figure><figcaption> <strong>Michael Tanaka, Miracl<\/strong> <\/figcaption><i class=\"icon\" data-icon=\"z\"><\/i> <\/p>\n<\/blockquote>\n<p>Retailers using the PrestaShop platform should immediately make sure their websites and all modules are updated to the latest version, which should prevent them from being exposed to known or actively exploited SQL injection bugs.<\/p>\n<p>The supplier added that there was a chance attackers were exploiting the rarely used MySQL Smarty cache storage feature in their attack vector (which is disabled by default but can be remotely enabled), so users may also wish to physically disable the feature in PrestaShop\u2019s code to cut off this particular method.<\/p>\n<p>More information, including indicators of compromise (IoCs), <a href=\"https:\/\/build.prestashop.com\/news\/major-security-vulnerability-on-prestashop-websites\/\">is available from PrestaShop<\/a>.<\/p>\n<p>Chris Hauk, consumer privacy advocate at&nbsp;cyber security guidance and online privacy specialist <a href=\"https:\/\/pixelprivacy.com\/\">Pixel Privacy<\/a>, said PrestaShop\u2019s guidance should be implemented urgently.&nbsp;<\/p>\n<p>\u201cPrestaShop users will want to disable the feature being used for this exploit to break this attack chain. This underscores the need for site administrators to keep their systems updated to the latest version of the operating systems, databases and apps,\u201d said Hauk.<\/p>\n<p>Michael Tanaka, chief commercial officer at multifactor authentication (MFA) supplier <a href=\"https:\/\/miracl.com\/\">Miracl<\/a>, added: \u201cEvidence today showing how the PrestaShop platform is being exploited by hackers is a stark reminder that platforms need to be updated regularly to ensure you have the latest security benefits.<\/p>\n<p>\u201cNot only maintenance patches, but also new technologies such as zero-knowledge proofs and protocols [ZKPs] that minimise the use of personal data will further harden any platform against attack,\u201d said Tanaka.<\/p>\n<p><strong>&nbsp;<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>PrestaShop, a developer of open source e-commerce software used by hundreds of thousands of small, independent retailers as the foundations of their online presence, has warned of a serious vulnerability that, left unaddressed, would allow attackers to achieve arbitrary code execution and steal customer card data. Tracked as CVE-2022-36408, the vulnerability first came to light [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":41164,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-41163","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/41163","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=41163"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/41163\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/41164"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=41163"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=41163"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=41163"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}