CVE-2022-21686 - CVE House
Back to Database
Status published Critical CVE-2022-21686

Server Side Twig Template Injection in PrestaShop

Vulnerability Description

PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is fixed in version 1.7.8.3. There are no known workarounds.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-21686

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

PrestaShop
Vulnerable Versions:
>= 1.7.0.0, < 1.7.8.3

Timeline

Official Publish: January 26th, 2022
Last Modified: April 23rd, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)