First published: Fri Nov 17 2023(Updated: )
In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.
|Affected Software||Affected Version||How to fix|
|Common-services Sonice Retour||<=2.1.0|
CVE-2023-45382 is a vulnerability in the module SoNice Retour (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop that allows a guest to download personal information without restriction by performing a path traversal attack.
The severity of CVE-2023-45382 is high with a CVSS score of 7.5.
An attacker can exploit CVE-2023-45382 by performing a path traversal attack to download personal information without restriction.
To fix CVE-2023-45382, update the SoNice Retour module to version 2.1.1 or higher provided by Common-Services for PrestaShop.
More information about CVE-2023-45382 can be found at the following references: [Reference 1](https://common-services.com/fr/home-fr/) and [Reference 2](https://security.friendsofpresta.org/modules/2023/11/16/sonice_retour.html).