CVE-2024-25840: Path Traversal
In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25840?
CVE-2024-25840 is classified as a high severity vulnerability due to unrestricted access to personal information.
How do I fix CVE-2024-25840?
To fix CVE-2024-25840, update the PrestaSalesManager module to version 9.0.1 or later.
What does CVE-2024-25840 affect?
CVE-2024-25840 affects the Account Manager | Sales Representative & Dealers | CRM module for PrestaShop, specifically versions up to 9.0.
What type of attack is CVE-2024-25840 related to?
CVE-2024-25840 is associated with a path traversal attack that allows unauthorized access to personal information.
Who is affected by CVE-2024-25840?
Any users of the PrestaSalesManager module for PrestaShop version 9.0 or earlier are potentially vulnerable to CVE-2024-25840.