PT-2024-29497 · Unknown+1 · Prestashop+1

Clotairer

·

Published

2024-07-26

·

Updated

2024-07-29

·

CVE-2024-41670

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions PrestaShop versions prior to 6.4.2 PrestaShop 1.6 versions prior to 3.18.1
Description A logical weakness in the "PayPal Official" module for PrestaShop can be exploited by a malicious customer to confirm an order even if the payment is declined by PayPal. This issue occurs when webhooks are disabled during the capture of a payment, allowing a threat actor to create an accepted order with a fraudulent payment support.
Recommendations For PrestaShop versions prior to 6.4.2, update to version 6.4.2 to resolve the issue. For PrestaShop 1.6 versions prior to 3.18.1, update to version 3.18.1 to resolve the issue. As a temporary workaround, consider enabling webhooks and verifying they are callable to minimize the risk of exploitation.

Exploit

Fix

Incorrect Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-41670
GHSA-W3W3-J3MH-3354

Affected Products

Paypal Official
Prestashop