Record summary

CVE-2023-30192 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 27, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryCRITICALPrestaShop 'possearchproducts' <= 1.7 - SQL InjectionCVSS 9.8

In the module “Search Products” (possearchproducts) from PosThemes for PrestaShop, a guest can perform SQL injection in affected versions.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the PrestaShop application and its underlying database.

Remediation

Apply the latest security patches and updates from the vendor to address this vulnerability.

WeaknessesCWE-89
Authorsmastercho
Template tagscvecve2023prestashopsqlitime-based-sqlivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: http.component:"prestashop"

Source: ProjectDiscovery

References

3