friends-of-presta.github.io
https://friends-of-presta.github.io/security-advisories/modules/2023/05/11/possearchproducts.html CVE-2023-30192
CRITICALNuclei
PrestaShop 'possearchproducts' <= 1.7 - SQL Injection
Record summary
CVE-2023-30192 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 27, 2025 · Source: CVE List
Nuclei templates
1ProjectDiscoveryCRITICALPrestaShop 'possearchproducts' <= 1.7 - SQL InjectionCVSS 9.8
In the module “Search Products” (possearchproducts) from PosThemes for PrestaShop, a guest can perform SQL injection in affected versions.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the PrestaShop application and its underlying database.
Remediation
Apply the latest security patches and updates from the vendor to address this vulnerability.
WeaknessesCWE-89
Authorsmastercho
Template tagscvecve2023prestashopsqlitime-based-sqlivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: http.component:"prestashop"
https://nvd.nist.gov/vuln/detail/CVE-2023-30192 https://security.friendsofpresta.org/modules/2023/05/11/possearchproducts.html
Source: ProjectDiscovery
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-30192 themeforest.net
https://themeforest.net/user/posthemes/portfolio