Skip to content

CVE-2023-30153

An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0 and 3.7.1, allows remote attackers to execute arbitrary SQL commands via the ajax.php front controller..This CVE has a CVSS3.1 score of 9.8 and a Base Severity of CRITICAL.

InfoDetails
CVE IDCVE-2023-30153
CVE StatePUBLISHED
BaseScore9.8
BaseSeverityCRITICAL
VectorStringCVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N
VersionNA

References for CVE-2023-30153 :
https://addons.prestashop.com/en/payment-card-wallet/8795–payplug-accept-customer-payments-wherever-they-are.html
https://security.friendsofpresta.org/module/2023/07/18/payplug.html

Metric TypeMetric Score
AttackVector(AV)NETWORK
AttackComplexity(AC)LOW
PrivilegesRequired(PR)NONE
UserInteraction(UI)NONE
Scope(S)UNCHANGED
Confidentiality(C)HIGH
Availability(A)HIGH
Integrity(I)HIGH