SQL Injection Vulnerability in AfterMail Module for PrestaShop (before version 2.2.1) via Multiple Parameters

SQL Injection Vulnerability in AfterMail Module for PrestaShop (before version 2.2.1) via Multiple Parameters

CVE-2023-30154 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Multiple improper neutralization of SQL parameters in module AfterMail (aftermailpresta) for PrestaShop, before version 2.2.1, allows remote attackers to perform SQL injection attacks via `id_customer`, `id_conf`, `id_product` and `token` parameters in `aftermailajax.php via the 'id_product' parameter in hooks DisplayRightColumnProduct and DisplayProductButtons.

Learn more about our Cis Benchmark Audit For Microsoft Sql Server.