CVE-2023-46354: High severity MyPrestaModules Orders \(csv\, Excel\) Export Pro Prestashop vulnerability
In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from pscustomer/psaddress tables such as name / surname / email / phone number / full postal address.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-46354.
What is the title of this vulnerability?
The title of this vulnerability is 'In the module Orders (CSV Excel) Export PRO (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop'.
What is the severity of CVE-2023-46354?
The severity of CVE-2023-46354 is high (7.5).
What is the affected software for this vulnerability?
The affected software for this vulnerability is the 'Orders (CSV, Excel) Export PRO' module < 5.2.0 from MyPrestaModules for PrestaShop.
How can this vulnerability be exploited?
This vulnerability allows a guest to download personal information without restriction, leading to a potential leak of personal information.