S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 26, 2025

CVE-2023-29630 Scanner

CVE-2023-29630 Scanner - SQL Injection vulnerability in PrestaShop Jms Vertical MegaMenu

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.6k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
CVECVE-2023-29630
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

PrestaShop jmsmegamenu 1.1.x and 2.0.x is vulnerable to SQL Injection via ajax_jmsmegamenu.php.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

PrestaShop Jms Vertical MegaMenu is an essential module for e-commerce platforms, particularly those using Joommasters PrestaShop themes. It offers various configurations for displaying vertical mega menus, enhancing user experience and site navigation. Predominantly used by site administrators and developers, this module is integrated into numerous e-commerce sites built on PrestaShop. Its versatility makes it a popular choice for customizing online store layouts. The integration is straightforward, empowering users to enhance functionality effectively. Overall, it's a powerful tool that supports site aesthetics and user navigation.

The identified vulnerability is a critical Blind SQL Injection found in the Jms Vertical MegaMenu module. This flaw can allow attackers to manipulate database queries, which are executed on the server-side. Unauthenticated remote users could exploit the vulnerability, resulting in the exposure of sensitive data or allowing the execution of dangerous operations. Attack vectors revolve around malicious input sent via specially crafted requests, taking advantage of weak security controls within the affected versions. The vulnerability poses significant security risks due to potential unauthorized data access and alterations.

The vulnerability is specifically located in the script handling ajax requests, known as ajax_jmsmegamenu.php. By injecting malicious SQL queries through this endpoint, attackers can bypass authentication or escalate privileges. It's exploited through crafted URL paths or request parameters, designed to deceive the SQL parser. Version parsing errors may exacerbate this vulnerability, as seen in versions before 2.0.9. Mitigating this issue entails input validation and implementing stringent access controls to prevent unauthorized SQL query execution. This highlights the necessity for secure coding practices.

Exploiting this SQL Injection vulnerability can have severe consequences for affected systems. Attackers might gain unauthorized access to confidential information, disrupt database integrity, or even manipulate site content. The exploitation could lead to data leaks, privilege escalation, and potentially shutting down services, damaging the online reputation of affected e-commerce platforms. Patch deployment and continuous monitoring are crucial to preclude exploitation attempts. Regular audits could assist in uncovering similar flaws, ensuring a secure operational environment.

REFERENCES

Solution Advice
  • Apply the latest security patch provided by the module developer to mitigate this issue.
  • Regularly update the Jms Vertical MegaMenu module to the latest available version to avoid any security vulnerabilities.
  • Implement strong input validation on all user inputs to prevent SQL injection attacks.
  • Conduct periodic security audits and code reviews to identify and resolve potential security issues.
  • Restrict access to sensitive backend configurations only to authorized personnel with secure authentication mechanisms.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-29630 Scanner - SQL Injection vulnerability in PrestaShop Jms Vertical MegaMenu | S4E