Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-43664

Опубликовано: 28 сент. 2023
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list all modules without any access rights: method ajaxProcessGetPossibleHookingListForModule doesn't check access rights. This issue has been addressed in commit 15bd281c which is included in version 8.1.2. Users are advised to upgrade. There are no known workaround for this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*
Версия до 8.1.2 (исключая)

EPSS

Процентиль: 47%
0.00239
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 4.3
github
больше 2 лет назад

PrestaShop allows employee without any access rights to list all installed modules

EPSS

Процентиль: 47%
0.00239
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-269