PT-2023-29537 · Prestashop · Order Duplicator Module

Published

2023-11-07

·

Updated

2024-09-05

·

CVE-2023-45380

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Order Duplicator module for PrestaShop versions <= 1.1.7
Description The issue allows a guest to download personal information without restriction due to a lack of permissions control. This includes accessing data from the ps customer and ps address tables, such as name, surname, phone number, and full postal address.
Recommendations For versions <= 1.1.7, update to a version greater than 1.1.7 to resolve the issue. As a temporary workaround, consider restricting access to the Order Duplicator module until a patch is available. Additionally, restrict access to the ps customer and ps address tables to minimize the risk of exploitation.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2023-45380

Affected Products

Order Duplicator Module