PT-2023-28909 · Unknown · Prestashop

Jolelievre

·

Published

2023-09-28

·

Updated

2024-03-06

·

CVE-2023-43664

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PrestaShop versions prior to 8.1.2
Description The issue concerns the PrestaShop Back office interface, where an employee can list all modules without any access rights due to the method ajaxProcessGetPossibleHookingListForModule not checking access rights. This issue has been addressed in a commit included in version 8.1.2.
Recommendations For versions prior to 8.1.2, upgrade to version 8.1.2 to resolve the issue. As a temporary workaround, consider restricting access to the ajaxProcessGetPossibleHookingListForModule method until the upgrade is applied.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BIT-PRESTASHOP-2023-43664
CVE-2023-43664
GHSA-GVRG-62JP-RF7J

Affected Products

Prestashop