Record summary

CVE-2023-30194 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 21, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 27, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALPrestashop posstaticfooter <= 1.0.0 - SQL InjectionCVSS 9.8

Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().

Impact

Unauthenticated attackers can execute arbitrary SQL commands to extract database contents including customer data, orders, payment information, and administrative credentials from the PrestaShop database.

Remediation

Upgrade to the latest version of the posstaticfooter module from posthemes.

WeaknessesCWE-89
Authorsdaffainfo
Template tagscvecve2023prestashoppoststaticfootersqlivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:prestashop:poststaticfooter:*:*:*:*:*:*:*:*
Shodan: html:"posstaticfooter"

Source: ProjectDiscovery

References

3