CVE-2023-43664
Summary
| CVE | CVE-2023-43664 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-28 19:15:00 UTC |
| Updated | 2023-10-03 00:18:00 UTC |
| Description | PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list all modules without any access rights: method `ajaxProcessGetPossibleHookingListForModule` doesn't check access rights. This issue has been addressed in commit `15bd281c` which is included in version 8.1.2. Users are advised to upgrade. There are no known workaround for this issue. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Merge pull request from GHSA-gvrg-62jp-rf7j · PrestaShop/PrestaShop@15bd281 · GitHub |
MISC |
github.com |
|
| Employee without any access rights can list all installed modules · Advisory · PrestaShop/PrestaShop · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995455 PHP (Composer) Security Update for prestashop/prestashop (GHSA-gvrg-62jp-rf7j)