PT-2024-26131 · Unknown · Prestashop

Samuel Bodevin

·

Published

2024-05-14

·

Updated

2025-01-21

·

CVE-2024-34717

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PrestaShop version 8.1.5
Description PrestaShop is an open source e-commerce web application. The issue allows any invoice to be downloaded from the front-office in anonymous mode by supplying a random secure key parameter in the url.
Recommendations For PrestaShop version 8.1.5, upgrade to version 8.1.6 to resolve the issue. As a temporary workaround, consider restricting access to invoice downloads until the patch is applied.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BIT-PRESTASHOP-2024-34717
CVE-2024-34717
GHSA-7PJR-2RGH-FC5G

Affected Products

Prestashop