S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-30150 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in PrestaShop leocustomajax affects v. 1.0 and 1.0.0.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-30150
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

PrestaShop leocustomajax 1.0 and 1.0.0 is a module designed to add custom AJAX functionality to your PrestaShop eCommerce store. The module allows you to create custom AJAX scripts without having to write a single line of code. You can customize the content of your pages, add new elements, and much more.

The CVE-2023-30150 vulnerability detected in the PrestaShop leocustomajax module makes it vulnerable to SQL injection via modules/leocustomajax/leoajax.php. SQL injection is a type of web vulnerability that allows an attacker to inject malicious SQL statements into a vulnerable web application. This vulnerability can be exploited by malicious actors to gain access to sensitive data.

When exploited, the CVE-2023-30150 vulnerability in the PrestaShop leocustomajax module can lead to the theft of sensitive data such as user logins, passwords, and credit card information. Attackers can also manipulate data or take control of the website. This can cause reputational damage to the eCommerce store and its owners.

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. The platform provides a comprehensive cybersecurity solution for businesses of all sizes. With a wide range of features, such as vulnerability scanning, web application firewall, and malware detection, you can ensure the security of your online assets. Moreover, you can get real-time alerts and reports on potential security threats, which helps you to take prompt actions to protect your eCommerce store. Protect your eCommerce store with s4e.io today!

 

REFERENCES

Solution Advice

To protect against the CVE-2023-30150 vulnerability in the PrestaShop leocustomajax module, the following precautions can be taken:

  • Keep your eCommerce platform updated with the latest version of the PrestaShop leocustomajax module.
  • Use a web application firewall to prevent SQL injection attacks.
  • Use parameterized queries to avoid SQL injection attacks.
  • Limit the privileges of the database user to prevent unauthorized access.
  • Regularly scan your website for vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-30150 scanner - SQL Injection (SQLi) vulnerability in PrestaShop leocustomajax S4E