Improper Privilege Management in Prestashop
CVE-2023-43663

6.3MEDIUM

Key Information:

Vendor

Prestashop

Vendor
CVE Published:
28 September 2023

What is CVE-2023-43663?

PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit ce1f6708 addresses this issue and is included in version 8.1.2. Users are advised to upgrade. There are no known workarounds for this issue.

Affected Version(s)

PrestaShop < 8.1.2

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-43663 : Improper Privilege Management in Prestashop