PT-2024-29497 · Unknown+1 · Prestashop+1
Clotairer
·
Published
2024-07-26
·
Updated
2024-07-29
·
CVE-2024-41670
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PrestaShop versions prior to 6.4.2
PrestaShop 1.6 versions prior to 3.18.1
Description
A logical weakness in the "PayPal Official" module for PrestaShop can be exploited by a malicious customer to confirm an order even if the payment is declined by PayPal. This issue occurs when webhooks are disabled during the capture of a payment, allowing a threat actor to create an accepted order with a fraudulent payment support.
Recommendations
For PrestaShop versions prior to 6.4.2, update to version 6.4.2 to resolve the issue.
For PrestaShop 1.6 versions prior to 3.18.1, update to version 3.18.1 to resolve the issue.
As a temporary workaround, consider enabling webhooks and verifying they are callable to minimize the risk of exploitation.
Exploit
Fix
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Paypal Official
Prestashop