CVE-2023-30839
PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vulnerability. A BO user can write, update, and delete in the database, even without having specific rights. PrestaShop 8.0.4 and 1.7.8.9 contain a patch for this issue. There are no known workarounds.
- Affected products
- Prestashop
- Prestashop
- < 1.7.8.9, 8.0.4
- Fix
- Available
- CVSS 3.1
- 9.9 CRITICAL
- EPSS
- 1.7% (76th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2023-04-25
CVE-2023-30839 at NVD
3 known exploits for CVE-2023-30839
Proof-of-concept code and exploit modules indexed by Sploitus