CVE-2023-45382: Path Traversal
In the module "SoNice Retour" (soniceretour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-45382?
CVE-2023-45382 is a vulnerability in the module SoNice Retour (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop that allows a guest to download personal information without restriction by performing a path traversal attack.
What is the severity of CVE-2023-45382?
The severity of CVE-2023-45382 is high with a CVSS score of 7.5.
How can an attacker exploit CVE-2023-45382?
An attacker can exploit CVE-2023-45382 by performing a path traversal attack to download personal information without restriction.
How can I fix CVE-2023-45382?
To fix CVE-2023-45382, update the SoNice Retour module to version 2.1.1 or higher provided by Common-Services for PrestaShop.
Where can I find more information about CVE-2023-45382?
More information about CVE-2023-45382 can be found at the following references: [Reference 1](https://common-services.com/fr/home-fr/) and [Reference 2](https://security.friendsofpresta.org/modules/2023/11/16/sonice_retour.html).