CVE-2023-30151: Boxtal Envoimoinscher

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

A SQL injection vulnerability in the Boxtal (envoimoinscher) module for PrestaShop, after version 3.1.10, allows remote attackers to execute arbitrary SQL commands via the `key` GET parameter.

Affected products

  • Boxtal Envoimoinscher: before 3.1.10 (fixed in 3.1.10)

Published 2023-07-13. Last modified 2026-06-17.