QID 995455
Date Published: 2023-10-03
QID 995455: PHP (Composer) Security Update for prestashop/prestashop (GHSA-gvrg-62jp-rf7j)
In BO, an employee can list all modules without any access rights: method ajaxProcessGetPossibleHookingListForModule doesn't check access rights
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-gvrg-62jp-rf7j for updates and patch information.
Vendor References
- GHSA-gvrg-62jp-rf7j -
github.com/advisories/GHSA-gvrg-62jp-rf7j
CVEs related to QID 995455
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gvrg-62jp-rf7j | prestashop/prestashop |
|