First published: Mon Jun 24 2024(Updated: )
In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while SHOP is in maintenance mode. Due to a lack of permissions control, a guest can access the txt file which collect email when maintenance is enable which can lead to leak of personal information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Promokit.eu Theme settings | <=1.8.8 | |
Prestashop |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-36682 is considered a medium severity vulnerability due to unauthorized access to sensitive email data.
To fix CVE-2024-36682, update the Theme settings module to version 1.8.9 or later to ensure proper permissions are enforced.
CVE-2024-36682 affects users of the Theme settings module version 1.8.8 and earlier in PrestaShop installations.
The impact of CVE-2024-36682 is that unauthorized guests can download stored emails while the shop is in maintenance mode.
While not extremely common, CVE-2024-36682 highlights a specific issue in permission controls that can affect many PrestaShop users.