First published: Fri Nov 17 2023(Updated: )
In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Common-services Sonice Retour | <=2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-45382 is a vulnerability in the module SoNice Retour (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop that allows a guest to download personal information without restriction by performing a path traversal attack.
The severity of CVE-2023-45382 is high with a CVSS score of 7.5.
An attacker can exploit CVE-2023-45382 by performing a path traversal attack to download personal information without restriction.
To fix CVE-2023-45382, update the SoNice Retour module to version 2.1.1 or higher provided by Common-Services for PrestaShop.
More information about CVE-2023-45382 can be found at the following references: [Reference 1](https://common-services.com/fr/home-fr/) and [Reference 2](https://security.friendsofpresta.org/modules/2023/11/16/sonice_retour.html).