CVE-2024-34991: Infoleak
In the module "Axepta" (axepta) before 1.3.4 from Quadra Informatique for PrestaShop, a guest can download partial credit card information (expiry date) / postal address / email / etc. without restriction due to a lack of permissions control.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34991?
CVE-2024-34991 is considered a significant vulnerability due to the exposure of sensitive information like partial credit card details and personal data.
How do I fix CVE-2024-34991?
To fix CVE-2024-34991, upgrade the Axepta module to version 1.3.4 or later, which addresses the lack of permissions control.
Who is affected by CVE-2024-34991?
CVE-2024-34991 affects users of the Axepta module from Quadra Informatique on PrestaShop versions prior to 1.3.4.
What type of information can be accessed due to CVE-2024-34991?
CVE-2024-34991 allows unauthorized access to partial credit card information, email addresses, and postal addresses.
Is CVE-2024-34991 being actively exploited?
At this time, there are no public reports confirming that CVE-2024-34991 is being actively exploited.