PT-2023-28908 · Unknown · Prestashop
Jolelievre
·
Publicado
2023-09-28
·
Atualizado
2024-03-06
·
CVE-2023-43663
CVSS v3.1
6.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
PrestaShop versions prior to 8.1.2
Description
PrestaShop is an Open Source e-commerce web application. In affected versions, any module can be disabled or uninstalled from the back office, even with low user rights. This allows low privileged users to disable portions of a shop's functionality.
Recommendations
For versions prior to 8.1.2, upgrade to version 8.1.2 to resolve the issue. As a temporary workaround, consider restricting access to the back office for low privileged users until the upgrade is applied. There are no known workarounds for this issue other than upgrading to the fixed version.
Exploit
Correção
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Prestashop