No image available

LabelGrup.com FIX CVE-2022-36408 (for PrestaShop 1.6.1.X / 1.7.X)

A PrestaShop security patch module that fixes the CVE-2022-36408 / CVE-2022-31181 Chain SQL Injection vulnerability by replacing the affected core files on installation.

Developed by LabelGrup Networks SL, Manel Alonso

Get This Module Free on GitHub
License: Unknown Status: Unknown Health: Very Outdated

Info updated 1 month ago

Sources
Forks: 1 Last commit: Jul 28, 2022
Type
Module

Info checked: Mar 2, 2026

This module addresses a critical Chain SQL Injection vulnerability affecting PrestaShop stores, identified under CVE-2022-36408 and CVE-2022-31181. By installing it as a standard add-on, the module replaces or copies the necessary core files to patch the security flaw without requiring manual file editing. It provides a straightforward remediation path for store owners who cannot immediately upgrade their PrestaShop installation.

  • Patches CVE-2022-36408 and CVE-2022-31181 Chain SQL Injection vulnerabilities
  • Installs as a standard ZIP add-on — no manual file editing required
  • Uninstalling the module reverts the patched files, re-exposing the vulnerability
  • Leaves a residual "cvepatches" folder in the /classes directory upon uninstall, which must be removed manually

This module is intended for PrestaShop merchants who need a quick, installable fix for the Chain SQL Injection vulnerability and cannot apply the patch through other means. Store owners should be aware that removing the module will undo the security fix, and should plan accordingly to apply a permanent solution through a full platform upgrade when possible.

  • Reference
    lblfixer_cve_2022_36408

  • License
    Unknown
  • Status
    Unknown

Comments (0)

No customer reviews for the moment.
Loading...