PT-2023-29539 · Unknown · Prestashop+1

Published

2023-11-17

·

Updated

2024-08-12

·

CVE-2023-45382

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SoNice Retour module for PrestaShop versions up to 2.1.0
Description The issue allows a guest to download personal information without restriction by performing a path traversal attack. This is due to a lack of permissions control and a lack of control in the path name construction, enabling a guest to view all files on the information system.
Recommendations For SoNice Retour module for PrestaShop versions up to 2.1.0, consider disabling the module until a patch is available to prevent path traversal attacks. Restrict access to sensitive files and directories to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-45382

Affected Products

Prestashop
Sonice Retour