Логотип exploitDog
bind:CVE-2023-45382
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-45382

Количество 2

Количество 2

nvd логотип

CVE-2023-45382

около 2 лет назад

In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-p32g-h5j4-3gxx

около 2 лет назад

In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-45382

In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-p32g-h5j4-3gxx

In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.

CVSS3: 7.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу