PT-2023-28908 · Unknown · Prestashop

Jolelievre

·

Publicado

2023-09-28

·

Atualizado

2024-03-06

·

CVE-2023-43663

CVSS v3.1

6.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions PrestaShop versions prior to 8.1.2
Description PrestaShop is an Open Source e-commerce web application. In affected versions, any module can be disabled or uninstalled from the back office, even with low user rights. This allows low privileged users to disable portions of a shop's functionality.
Recommendations For versions prior to 8.1.2, upgrade to version 8.1.2 to resolve the issue. As a temporary workaround, consider restricting access to the back office for low privileged users until the upgrade is applied. There are no known workarounds for this issue other than upgrading to the fixed version.

Exploit

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-PRESTASHOP-2023-43663
CVE-2023-43663
GHSA-6JMF-2PFC-Q9M7

Produtos afetados

Prestashop