CVE-2023-30151: SQL Injection
A SQL injection vulnerability in the Boxtal (envoimoinscher) module for PrestaShop, after version 3.1.10, allows remote attackers to execute arbitrary SQL commands via the key GET parameter.
Other sources
A SQL injection vulnerability in the Boxtal (envoimoinscher) module for PrestaShop, after version 3.1.10, allows remote authenticated users to execute arbitrary SQL commands via the key GET parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-30151?
CVE-2023-30151 is a SQL injection vulnerability in the Boxtal (envoimoinscher) module for PrestaShop after version 3.1.10.
How does CVE-2023-30151 affect PrestaShop?
CVE-2023-30151 allows remote authenticated users to execute arbitrary SQL commands in PrestaShop via the 'key' GET parameter.
What is the severity of CVE-2023-30151?
CVE-2023-30151 is considered critical with a severity score of 9.8 on a scale of 10.
Which versions of PrestaShop are affected by CVE-2023-30151?
PrestaShop versions up to but excluding 3.1.10 are affected by CVE-2023-30151.
How can I fix CVE-2023-30151?
To fix CVE-2023-30151, users should update to a version of PrestaShop that is newer than 3.1.10 and apply any available patches or security updates.