SQL Injection Vulnerability in Postfinance Module for PrestaShop
CVE-2023-31671
9.8CRITICAL
What is CVE-2023-31671?
The Postfinance module for PrestaShop versions up to 17.1.13 is vulnerable to SQL Injection, which could allow attackers to execute arbitrary SQL commands through unvalidated input in the PostfinanceValidationModuleFrontController::postProcess() function. This vulnerability exposes sensitive data and can compromise the integrity of the database. It is crucial for users of affected versions to apply patches or updates to mitigate potential attacks.