PT-2023-19956 · Unknown · Prestashop
Matthieu-Rolland
·
Publicado
2023-03-13
·
Atualizado
2024-03-06
·
CVE-2023-25170
CVSS v3.1
5.0
Média
| Vetor | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
PrestaShop versions prior to 8.0.1
Description
PrestaShop is an open source e-commerce web application that is vulnerable to cross-site request forgery (CSRF). When authenticating users, PrestaShop preserves session attributes, which does not clear CSRF tokens upon login. This might enable same-site attackers to bypass the CSRF protection mechanism by performing an attack similar to a session-fixation.
Recommendations
For versions prior to 8.0.1, update to version 8.0.1 to resolve the issue. As a temporary workaround, consider clearing CSRF tokens upon login to prevent same-site attackers from bypassing the CSRF protection mechanism. Restrict access to sensitive areas of the application to minimize the risk of exploitation.
Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Prestashop