First published: Thu May 04 2023(Updated: )
PrestaShop scexportcustomers <= 3.6.1 is vulnerable to Incorrect Access Control. Due to a lack of permissions' control, a guest can access exports from the module which can lead to leak of personal information from customer table.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Prestashop Scexportcustomers | <=3.6.1 | |
<=3.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30282 is a vulnerability in PrestaShop scexportcustomers <= 3.6.1 that allows an unauthorized guest to access exports from the module, potentially resulting in the leakage of personal information from the customer table.
CVE-2023-30282 is classified as a high-severity vulnerability with a severity score of 7.5.
To fix CVE-2023-30282, you should update PrestaShop scexportcustomers module to a version above 3.6.1, where the vulnerability has been fixed.
You can find more information about CVE-2023-30282 at the following link: [https://friends-of-presta.github.io/security-advisories/modules/2023/05/02/scexportcustomers.html](https://friends-of-presta.github.io/security-advisories/modules/2023/05/02/scexportcustomers.html)
The affected software for CVE-2023-30282 is PrestaShop scexportcustomers <= 3.6.1.