{"id":"BIT-prestashop-2023-30151","details":"A SQL injection vulnerability in the Boxtal (envoimoinscher) module for PrestaShop, after version 3.1.10, allows remote attackers to execute arbitrary SQL commands via the `key` GET parameter.","modified":"2026-07-16T09:11:45.299177142Z","published":"2024-03-06T11:05:05.610Z","withdrawn":"2026-07-16T09:00:04.056674276Z","database_specific":{"severity":"Critical","cpes":["cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*"]},"references":[{"type":"WEB","url":"https://addons.prestashop.com/en/shipping-carriers/1755-boxtal-connect-turnkey-shipping-solution.html"},{"type":"WEB","url":"https://help.boxtal.com/hc/fr/articles/360001342977-J-ai-besoin-du-module-PrestaShop-ancienne-version-Boxtal-Envoimoinscher-pour-mon-site"},{"type":"WEB","url":"https://security.friendsofpresta.org/module/2023/06/20/envoimoinscher.html"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-30151"}],"affected":[{"package":{"name":"prestashop","ecosystem":"Bitnami","purl":"pkg:bitnami/prestashop"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.1.10"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/prestashop/BIT-prestashop-2023-30151.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}],"schema_version":"1.7.3"}