csvfeeds- PrestaShop module vulnerability (CVE-2023-46355)

Modulecsvfeeds

Score

5.3 Medium

Date publish

27-11-2023

Versiones afectadas

  • Less than 2.6.1

Description

In the module "CSV Feeds PRO" (csvfeeds) < 2.6.1 from Bl Modules for PrestaShop, a guest can download personal information without restriction. Due to too permissive access control which does not force administrator to use password on feeds, a guest can access exports from the module which can lead to leaks of personal information from ps_customer / ps_order table such as name / surname / email / phone number / postal address.

References

Metrics

cvssMetricV31
sourcenvd@nist.gov
typePrimary
version3.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
baseScore5.3
baseSeverityMEDIUM
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredNONE
userInteractionNONE
scopeUNCHANGED
confidentialityImpactLOW
integrityImpactNONE
availabilityImpactNONE
exploitabilityScore3.9
impactScore1.4
Scroll al inicio