High severity7.5NVD Advisory· Published Dec 7, 2021· Updated Jun 17, 2026
CVE-2021-43789
CVE-2021-43789
Description
PrestaShop is an Open Source e-commerce web application. Versions of PrestaShop prior to 1.7.8.2 are vulnerable to blind SQL injection using search filters with orderBy and sortOrder parameters. The problem is fixed in version 1.7.8.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
prestashop/prestashopPackagist | >= 1.7.5.0, < 1.7.8.2 | 1.7.8.2 |
Affected products
3cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*range: >=1.7.5.0,<1.7.8.2
- (no CPE)range: >= 1.7.5.0, <= 1.7.8.1
Patches
Vulnerability mechanics
References
7- github.com/PrestaShop/PrestaShop/issues/26623nvdIssue TrackingThird Party AdvisoryWEB
- github.com/PrestaShop/PrestaShop/releases/tag/1.7.8.2nvdRelease NotesThird Party AdvisoryWEB
- github.com/PrestaShop/PrestaShop/security/advisories/GHSA-6xxj-gcjq-wgf4nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-6xxj-gcjq-wgf4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-43789ghsaADVISORY
- cwe.mitre.org/data/definitions/89.htmlghsaWEB
- github.com/PrestaShop/PrestaShop/commit/6482b9ddc9dcebf7588dbfd616d2d635218408d6ghsaWEB
News mentions
0No linked articles in our index yet.