First published: Wed Dec 06 2023(Updated: )
In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from ps_customer/ps_address tables such as name / surname / email / phone number / full postal address.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Myprestamodules Orders (csv, Excel) Export Pro | <5.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-46354.
The title of this vulnerability is 'In the module Orders (CSV Excel) Export PRO (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop'.
The severity of CVE-2023-46354 is high (7.5).
The affected software for this vulnerability is the 'Orders (CSV, Excel) Export PRO' module < 5.2.0 from MyPrestaModules for PrestaShop.
This vulnerability allows a guest to download personal information without restriction, leading to a potential leak of personal information.