Описание
PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit ce1f6708 addresses this issue and is included in version 8.1.2. Users are advised to upgrade. There are no known workarounds for this issue.
Ссылки
- Patch
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 8.1.2 (исключая)
cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*
EPSS
Процентиль: 28%
0.00102
Низкий
6.3 Medium
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-269
Связанные уязвимости
CVSS3: 4.3
github
больше 2 лет назад
PrestaShop allows users to uninstall modules from backoffice, even with low rights
EPSS
Процентиль: 28%
0.00102
Низкий
6.3 Medium
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-269