Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6jmf-2pfc-q9m7

Опубликовано: 28 сент. 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

PrestaShop allows users to uninstall modules from backoffice, even with low rights

Impact

Any module can be disabled or uninstalled from back office, even with low user right.

Patches

8.1.2

Workarounds

none

References

Пакеты

Наименование

prestashop/prestashop

composer
Затронутые версииВерсия исправления

< 8.1.2

8.1.2

EPSS

Процентиль: 29%
0.00102
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 6.3
nvd
больше 2 лет назад

PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit `ce1f6708` addresses this issue and is included in version 8.1.2. Users are advised to upgrade. There are no known workarounds for this issue.

EPSS

Процентиль: 29%
0.00102
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-269