CVE-2023-30153: SQL Injection
Published Jul 18, 2023
·Updated
An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0 and 3.7.1, allows remote attackers to execute arbitrary SQL commands via the ajax.php front controller.
Affected Software
1 affected component
Prestashop Payplug Prestashop>=3.6.0<3.8.2
Remediation
Event History
Jul 18, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
07:15 PM
Description
Frequently Asked Questions
1
What is CVE-2023-30153?
CVE-2023-30153 is an SQL injection vulnerability in the Payplug module for PrestaShop.
2
What is the severity of CVE-2023-30153?
The severity of CVE-2023-30153 is critical with a CVSS score of 9.8.
3
Which versions of PrestaShop are affected by CVE-2023-30153?
Versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0, and 3.7.1 of PrestaShop are affected by CVE-2023-30153.
4
How can a remote attacker exploit CVE-2023-30153?
A remote attacker can exploit CVE-2023-30153 by executing arbitrary SQL commands via the ajax.php front controller.
5
What is the fix for CVE-2023-30153?
To fix CVE-2023-30153, update to PrestaShop version 3.8.2 or higher.