Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2023-30194 โ€” AI Deep Analysis Summary

CVSS 9.8 ยท Critical

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: PrestaShop module `poststaticfooter` (v1.0.0 and earlier) suffers from **SQL Injection**.โ€ฆ

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **Root Cause**: The function `poststaticfooter::getPosCurrentHook()` is vulnerable. <br>โš ๏ธ **Flaw**: It fails to properly sanitize user input before executing SQL commands, allowing malicious payloads to be injected.

Q3Who is affected? (Versions/Components)

๐Ÿ“ฆ **Affected**: PrestaShop installations using the **poststaticfooter** module. <br>๐Ÿ“… **Version**: Version **1.0.0** and any prior versions are at risk.

Q4What can hackers do? (Privileges/Data)

๐Ÿ•ต๏ธ **Capabilities**: Hackers can execute arbitrary SQL commands. <br>๐Ÿ”“ **Impact**: High risk of **Confidentiality**, **Integrity**, and **Availability** loss.โ€ฆ

Q5Is exploitation threshold high? (Auth/Config)

๐Ÿ”“ **Threshold**: **LOW**. <br>๐ŸŒ **Access**: Network Accessible (AV:N). <br>๐Ÿ”‘ **Auth**: No Privileges Required (PR:N). <br>๐Ÿ‘๏ธ **UI**: No User Interaction Needed (UI:N). Easy to exploit remotely.

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿ“œ **Public Exp?**: **YES**. <br>๐Ÿ”— **PoC**: Available via ProjectDiscovery Nuclei templates. <br>๐ŸŒ **Wild Exp**: Likely, given the low complexity and lack of auth requirements.

Q7How to self-check? (Features/Scanning)

๐Ÿ” **Self-Check**: Scan for the **poststaticfooter** module. <br>๐Ÿ› ๏ธ **Tool**: Use Nuclei with the specific CVE-2023-30194 template. <br>๐Ÿ“‹ **Verify**: Check if the module version is โ‰ค 1.0.0.

Q8Is it fixed officially? (Patch/Mitigation)

๐Ÿฉน **Fix**: Update the **poststaticfooter** module to a version **greater than 1.0.0**. <br>๐Ÿ“ข **Source**: Refer to Friends of Presta security advisories for official patch details.

Q9What if no patch? (Workaround)

๐Ÿšง **No Patch?**: **Disable** the `poststaticfooter` module immediately. <br>๐Ÿ›‘ **Mitigation**: If it must stay, restrict access via WAF rules to block SQL injection patterns in the `getPosCurrentHook` parameter.

Q10Is it urgent? (Priority Suggestion)

โšก **Urgency**: **CRITICAL**. <br>๐Ÿ”ฅ **Priority**: High. CVSS Score indicates **High** impact (C:H, I:H, A:H). Patch immediately to prevent data theft or site defacement.