PT-2023-19956 · Unknown · Prestashop

Matthieu-Rolland

·

Published

2023-03-13

·

Updated

2024-03-06

·

CVE-2023-25170

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions PrestaShop versions prior to 8.0.1
Description PrestaShop is an open source e-commerce web application that is vulnerable to cross-site request forgery (CSRF). When authenticating users, PrestaShop preserves session attributes, which does not clear CSRF tokens upon login. This might enable same-site attackers to bypass the CSRF protection mechanism by performing an attack similar to a session-fixation.
Recommendations For versions prior to 8.0.1, update to version 8.0.1 to resolve the issue. As a temporary workaround, consider clearing CSRF tokens upon login to prevent same-site attackers from bypassing the CSRF protection mechanism. Restrict access to sensitive areas of the application to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-PRESTASHOP-2023-25170
CVE-2023-25170
GHSA-3G43-X7QR-96PH

Affected Products

Prestashop