CVE-2023-43663: Improper Privilege Management in Prestashop
Impact Any module can be disabled or uninstalled from back office, even with low user right.
Patches 8.1.2
Workarounds none
References
Other sources
PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit ce1f6708 addresses this issue and is included in version 8.1.2. Users are advised to upgrade. There are no known workarounds for this issue.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-43663.
What is the impact of CVE-2023-43663?
The impact of CVE-2023-43663 is that any module can be disabled or uninstalled from the back office, even with low user rights.
How does CVE-2023-43663 affect PrestaShop?
CVE-2023-43663 affects PrestaShop by allowing low privileged users to disable portions of a shop's functionality.
What is the severity of CVE-2023-43663?
The severity of CVE-2023-43663 is medium, with a CVSS score of 6.7.
How can CVE-2023-43663 be fixed?
CVE-2023-43663 can be fixed by applying the commit ce1f6708 from the official PrestaShop repository.