First published: Wed May 31 2023(Updated: )
Incorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personal information without restriction by performing a path traversal attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webbax Myinventory | <1.6.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30197 is a vulnerability in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, which allows a guest to download personal information without restriction through a path traversal attack.
The severity of CVE-2023-30197 is high, with a severity value of 7.5.
CVE-2023-30197 allows a guest to download personal information without restriction in the My inventory module of PrestaShop.
The CVE-2023-30197 vulnerability can be exploited through a path traversal attack in the My inventory module of PrestaShop.
Yes, upgrading the My inventory module to version 1.6.7 or above fixes the CVE-2023-30197 vulnerability.