CVE-2023-30194
prestashop poststaticfooter Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2023-30194 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 21, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 27, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
poststaticfooterBrowse prestashop / poststaticfooter | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALPrestashop posstaticfooter <= 1.0.0 - SQL InjectionCVSS 9.8
Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().
Impact
Unauthenticated attackers can execute arbitrary SQL commands to extract database contents including customer data, orders, payment information, and administrative credentials from the PrestaShop database.
Remediation
Upgrade to the latest version of the posstaticfooter module from posthemes.
Source: ProjectDiscovery