CVE-2024-24309: Infoleak
Published Feb 23, 2024
·Updated
In the module "Survey TMA" (ecomizsurveytma) up to version 2.0.0 from Ecomiz for PrestaShop, a guest can download personal information without restriction.
Affected Software
3 affected components
ecomiz Survey Tma Prestashop<=2.0.0
ecomiz Survey TMA<=2.0.0
Prestashop PrestaShop
Event History
Feb 23, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24309?
CVE-2024-24309 is considered a high severity vulnerability due to its potential for unauthorized access to personal information.
2
How do I fix CVE-2024-24309?
To fix CVE-2024-24309, upgrade the Ecomiz Survey TMA module to a version above 2.0.0.
3
Who is affected by CVE-2024-24309?
Users of the Ecomiz Survey TMA module for PrestaShop up to version 2.0.0 are affected by CVE-2024-24309.
4
What type of vulnerability is CVE-2024-24309?
CVE-2024-24309 is classified as an information disclosure vulnerability.
5
Can a guest exploit CVE-2024-24309?
Yes, a guest can exploit CVE-2024-24309 to download personal information without any restrictions.