CVE-2023-47110: Any value can be changed in the configuration table by an employee having access to block reassurance module
Impact An ajax function in module blockreassurance allows modifying any value in the configuration table
Patches v5.1.4
Workarounds no workaround available
References
Other sources
blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax function in module blockreassurance allows modifying any value in the configuration table. This vulnerability has been patched in version 5.1.4.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-47110?
CVE-2023-47110 is a vulnerability in the blockreassurance module of PrestaShop that allows an employee with access to modify any value in the configuration table.
How can an employee exploit CVE-2023-47110?
An employee can exploit CVE-2023-47110 by using the ajax function in the blockreassurance module to modify any value in the configuration table.
Has CVE-2023-47110 been patched?
Yes, CVE-2023-47110 has been patched in version 5.1.4 of the blockreassurance module.
What is the severity of CVE-2023-47110?
CVE-2023-47110 has a severity rating of 9.1 (critical).
What is the Common Weakness Enumeration (CWE) ID of CVE-2023-47110?
The Common Weakness Enumeration (CWE) ID of CVE-2023-47110 is 284.