SQL Injection Vulnerability in Payplug Module for PrestaShop
CVE-2023-30153

9.8CRITICAL

Key Information:

Vendor

Prestashop

Status
Vendor
CVE Published:
18 July 2023

What is CVE-2023-30153?

An SQL injection vulnerability exists in the Payplug module for PrestaShop, allowing attackers to execute arbitrary SQL commands through the ajax.php front controller. This flaw affects multiple versions of the module, potentially compromising the integrity and confidentiality of the database. Users are urged to update to patched versions to mitigate this security risk.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.