CVE-2023-30200: Path Traversal
In the module “Image: WebP, Compress, Zoom, Lazy load, Alt & More” (ultimateimagetool) in versions up to 2.1.02 from Advanced Plugins for PrestaShop, a guest can download personal informations without restriction by performing a path traversal attack.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-30200?
CVE-2023-30200 is a critical vulnerability that allows unauthorized access to personal information through a path traversal attack.
How do I fix CVE-2023-30200?
To fix CVE-2023-30200, update the 'Ultimate Image Tool' module to version 2.1.03 or later.
Who is affected by CVE-2023-30200?
CVE-2023-30200 affects users of the 'Ultimate Image Tool' module for PrestaShop versions up to 2.1.02.
What type of attack is involved in CVE-2023-30200?
CVE-2023-30200 involves a path traversal attack that exploits improper input validation.
Can guest users exploit CVE-2023-30200?
Yes, guests can exploit CVE-2023-30200 to download personal information without restrictions.