First published: Fri Jun 02 2023(Updated: )
Improper Limitation of a Pathname leads to a Path Traversal vulnerability in the module King-Avis for Prestashop, allowing a user knowing the download token to read arbitrary local files.This issue affects King-Avis: before 17.3.15.
Credit: vulnerability@ncsc.ch
Affected Software | Affected Version | How to fix |
---|---|---|
Webbax King-avis | <17.3.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-3031.
The King-Avis module for Prestashop is affected by this vulnerability.
The severity of CVE-2023-3031 is medium with a CVSS score of 4.9.
An attacker with knowledge of the download token can exploit this vulnerability through a path traversal attack to read arbitrary local files.
To fix the CVE-2023-3031 vulnerability, update the King-Avis module to version 17.3.15 or later.