PT-2024-26131 · Unknown · Prestashop
Samuel Bodevin
·
Published
2024-05-14
·
Updated
2025-01-21
·
CVE-2024-34717
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PrestaShop version 8.1.5
Description
PrestaShop is an open source e-commerce web application. The issue allows any invoice to be downloaded from the front-office in anonymous mode by supplying a random
secure key parameter in the url.Recommendations
For PrestaShop version 8.1.5, upgrade to version 8.1.6 to resolve the issue. As a temporary workaround, consider restricting access to invoice downloads until the patch is applied.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prestashop