First published: Tue Jan 16 2024(Updated: )
An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily change an order status.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Prestashop | <2.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48926 has been classified as a high severity vulnerability due to its potential to allow unauthorized changes to order statuses.
To fix CVE-2023-48926, upgrade the PrestaShop Advanced Loyalty Program to version 2.3.4 or later.
CVE-2023-48926 affects users of the 202 ecommerce Advanced Loyalty Program for PrestaShop versions prior to 2.3.4.
CVE-2023-48926 is an authentication bypass vulnerability that allows unauthenticated attackers to alter order statuses.
CVE-2023-48926 was disclosed in 2023 and is a critical security issue for PrestaShop users.