In the module "Order Duplicator " Clone and Delete Existing Order" (orderduplicate) in version <= 1.1.7 from Silbersaiten for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can download personal information from ps_customer/ps_address tables such as name / surname / phone number / full postal address.
References
Link | Resource |
---|---|
https://security.friendsofpresta.org/modules/2023/11/07/orderduplicate.html | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2023-11-07T00:00:00
Updated: 2023-11-07T22:20:18.364288
Reserved: 2023-10-09T00:00:00
Link: CVE-2023-45380
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-11-07T23:15:07.780
Modified: 2023-11-15T15:35:36.637
Link: CVE-2023-45380
JSON object: View
Redhat Information
No data.
CWE