CVE-2023-31671: Webbax Postfinance

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

PrestaShop postfinance <= 17.1.13 is vulnerable to SQL Injection via PostfinanceValidationModuleFrontController::postProcess().

Affected products

  • Webbax Postfinance: before 17.1.14 (fixed in 17.1.14)

Published 2023-06-14. Last modified 2026-06-17.