PT-2023-28908 · Unknown · Prestashop
Jolelievre
·
Published
2023-09-28
·
Updated
2024-03-06
·
CVE-2023-43663
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
PrestaShop versions prior to 8.1.2
Description
PrestaShop is an Open Source e-commerce web application. In affected versions, any module can be disabled or uninstalled from the back office, even with low user rights. This allows low privileged users to disable portions of a shop's functionality.
Recommendations
For versions prior to 8.1.2, upgrade to version 8.1.2 to resolve the issue. As a temporary workaround, consider restricting access to the back office for low privileged users until the upgrade is applied. There are no known workarounds for this issue other than upgrading to the fixed version.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prestashop