Vulnerability Description
A SQL injection vulnerability in the Boxtal (envoimoinscher) module for PrestaShop, after version 3.1.10, allows remote attackers to execute arbitrary SQL commands via the `key` GET parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Boxtal | Envoimoinscher | < 3.1.10 |
Related Weaknesses (CWE)
References
- https://addons.prestashop.com/en/shipping-carriers/1755-boxtal-connect-turnkey-sNot Applicable
- https://help.boxtal.com/hc/fr/articles/360001342977-J-ai-besoin-du-module-PrestaPermissions RequiredThird Party Advisory
- https://security.friendsofpresta.org/module/2023/06/20/envoimoinscher.htmlExploitThird Party Advisory
- https://addons.prestashop.com/en/shipping-carriers/1755-boxtal-connect-turnkey-sNot Applicable
- https://help.boxtal.com/hc/fr/articles/360001342977-J-ai-besoin-du-module-PrestaPermissions RequiredThird Party Advisory
- https://security.friendsofpresta.org/module/2023/06/20/envoimoinscher.htmlExploitThird Party Advisory
FAQ
What is CVE-2023-30151?
CVE-2023-30151 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A SQL injection vulnerability in the Boxtal (envoimoinscher) module for PrestaShop, after version 3.1.10, allows remote attackers to execute arbitrary SQL commands via the `key` GET parameter.
How severe is CVE-2023-30151?
CVE-2023-30151 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-30151?
Check the references section above for vendor advisories and patch information. Affected products include: Boxtal Envoimoinscher.