PT-2023-22627 · King-Avis+1 · King-Avis+1

Testeurdestylos

·

Published

2023-06-02

·

Updated

2023-06-12

·

CVE-2023-3031

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions King-Avis versions prior to 17.3.15
Description The issue is related to Improper Limitation of a Pathname, leading to a Path Traversal vulnerability in the King-Avis module for Prestashop. This allows a user with knowledge of the download token to read arbitrary local files.
Recommendations For versions prior to 17.3.15, update to version 17.3.15 or later to resolve the issue. As a temporary workaround, consider restricting access to the download token to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-3031

Affected Products

King-Avis
Prestashop