CVE-2023-48926: Medium severity prestashop vulnerability
Published Jan 16, 2024
·Updated
An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily change an order status.
Affected Software
1 affected component
Prestashop Advanced Loyalty Program<2.3.4
Event History
Jan 16, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-48926?
CVE-2023-48926 has been classified as a high severity vulnerability due to its potential to allow unauthorized changes to order statuses.
2
How do I fix CVE-2023-48926?
To fix CVE-2023-48926, upgrade the PrestaShop Advanced Loyalty Program to version 2.3.4 or later.
3
Who is affected by CVE-2023-48926?
CVE-2023-48926 affects users of the 202 ecommerce Advanced Loyalty Program for PrestaShop versions prior to 2.3.4.
4
What type of vulnerability is CVE-2023-48926?
CVE-2023-48926 is an authentication bypass vulnerability that allows unauthenticated attackers to alter order statuses.
5
When was CVE-2023-48926 disclosed?
CVE-2023-48926 was disclosed in 2023 and is a critical security issue for PrestaShop users.