PT-2023-28908 · Unknown · Prestashop

Jolelievre

·

Published

2023-09-28

·

Updated

2024-03-06

·

CVE-2023-43663

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions PrestaShop versions prior to 8.1.2
Description PrestaShop is an Open Source e-commerce web application. In affected versions, any module can be disabled or uninstalled from the back office, even with low user rights. This allows low privileged users to disable portions of a shop's functionality.
Recommendations For versions prior to 8.1.2, upgrade to version 8.1.2 to resolve the issue. As a temporary workaround, consider restricting access to the back office for low privileged users until the upgrade is applied. There are no known workarounds for this issue other than upgrading to the fixed version.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BIT-PRESTASHOP-2023-43663
CVE-2023-43663
GHSA-6JMF-2PFC-Q9M7

Affected Products

Prestashop