Critical severity9.9NVD Advisory· Published Apr 25, 2023· Updated Jun 17, 2026
CVE-2023-30839
CVE-2023-30839
Description
PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vulnerability. A BO user can write, update, and delete in the database, even without having specific rights. PrestaShop 8.0.4 and 1.7.8.9 contain a patch for this issue. There are no known workarounds.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
prestashop/prestashopPackagist | >= 8.0.0, < 8.0.4 | 8.0.4 |
prestashop/prestashopPackagist | < 1.7.8.9 | 1.7.8.9 |
Affected products
4cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*range: <1.7.8.9
- (no CPE)range: >= 8.0.0, < 8.0.4
- osv-coords2 versions
>= 8.0.0, < 8.0.4+ 1 more
- (no CPE)range: >= 8.0.0, < 8.0.4
- (no CPE)range: >= 8.0.0, < 8.0.4
Patches
Vulnerability mechanics
References
7- github.com/PrestaShop/PrestaShop/commit/0f2a9b7fdd42d1dd3b21d4fad586a849642f3c30nvdPatchWEB
- github.com/PrestaShop/PrestaShop/commit/d1d27dc371599713c912b71bc2a455cacd7f2149nvdPatchWEB
- github.com/PrestaShop/PrestaShop/security/advisories/GHSA-p379-cxqh-q822nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-p379-cxqh-q822ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-30839ghsaADVISORY
- github.com/PrestaShop/PrestaShop/releases/tag/1.7.8.9ghsaWEB
- github.com/PrestaShop/PrestaShop/releases/tag/8.0.4ghsaWEB
News mentions
0No linked articles in our index yet.