First published: Wed Jun 19 2024(Updated: )
In the module "Login as customer PRO" (loginascustomerpro) <1.2.7 from Weblir for PrestaShop, a guest can access direct link to connect to each customer account of the Shop if the module is not installed OR if a secret accessible to administrator is stolen.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Weblir Login as Customer PRO | <1.2.7 | |
Prestashop |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-36677 is classified as a critical vulnerability due to its potential to allow unauthorized access to customer accounts.
To fix CVE-2024-36677, ensure that the 'Login as customer PRO' module is installed with the latest version or safeguard the secret from being accessed by unauthorized users.
CVE-2024-36677 affects users of the 'Login as customer PRO' module prior to version 1.2.7 on PrestaShop platforms.
Attackers can exploit CVE-2024-36677 to gain unauthorized access to any customer account by either bypassing the module or using a stolen secret.
A temporary workaround for CVE-2024-36677 is to restrict access to the secret used by administrators to prevent its theft.