PT-2023-19956 · Unknown · Prestashop
Matthieu-Rolland
·
Published
2023-03-13
·
Updated
2024-03-06
·
CVE-2023-25170
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
PrestaShop versions prior to 8.0.1
Description
PrestaShop is an open source e-commerce web application that is vulnerable to cross-site request forgery (CSRF). When authenticating users, PrestaShop preserves session attributes, which does not clear CSRF tokens upon login. This might enable same-site attackers to bypass the CSRF protection mechanism by performing an attack similar to a session-fixation.
Recommendations
For versions prior to 8.0.1, update to version 8.0.1 to resolve the issue. As a temporary workaround, consider clearing CSRF tokens upon login to prevent same-site attackers from bypassing the CSRF protection mechanism. Restrict access to sensitive areas of the application to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prestashop