CVE-2024-36677: High severity weblir login as customer pro vulnerability
In the module "Login as customer PRO" (loginascustomerpro) <1.2.7 from Weblir for PrestaShop, a guest can access direct link to connect to each customer account of the Shop if the module is not installed OR if a secret accessible to administrator is stolen.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36677?
CVE-2024-36677 is classified as a critical vulnerability due to its potential to allow unauthorized access to customer accounts.
How do I fix CVE-2024-36677?
To fix CVE-2024-36677, ensure that the 'Login as customer PRO' module is installed with the latest version or safeguard the secret from being accessed by unauthorized users.
Who is affected by CVE-2024-36677?
CVE-2024-36677 affects users of the 'Login as customer PRO' module prior to version 1.2.7 on PrestaShop platforms.
What can attackers do with CVE-2024-36677?
Attackers can exploit CVE-2024-36677 to gain unauthorized access to any customer account by either bypassing the module or using a stolen secret.
Are there any workarounds for CVE-2024-36677?
A temporary workaround for CVE-2024-36677 is to restrict access to the secret used by administrators to prevent its theft.