Critical severity9.8NVD Advisory· Published Jul 5, 2022· Updated Jun 17, 2026
CVE-2022-34972
CVE-2022-34972
Description
So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_value_id , opt_value_id , and subcate_value_id parameters at /index.php?route=extension/module/so_filter_shop_by/filter_data.
Affected products
3- cpe:2.3:a:so_filter_shop_by_project:so_filter_shop_by:3.0:*:*:*:*:opencart:*:*
- So Filter Shop/So Filter Shopdescription
Patches
Vulnerability mechanics
References
1- packetstormsecurity.com/files/167605/OpenCart-3.x-So-Filter-Shop-By-SQL-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.