CVE-2023-30154: Shoprunners Aftermail

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Multiple improper neutralization of SQL parameters in module AfterMail (aftermailpresta) for PrestaShop, before version 2.2.1, allows remote attackers to perform SQL injection attacks via `id_customer`, `id_conf`, `id_product` and `token` parameters in `aftermailajax.php via the 'id_product' parameter in hooks DisplayRightColumnProduct and DisplayProductButtons.

Affected products

Published 2023-10-14. Last modified 2026-06-17.