Vulnerability Description
In the module "Order Duplicator " Clone and Delete Existing Order" (orderduplicate) in version <= 1.1.7 from Silbersaiten for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can download personal information from ps_customer/ps_address tables such as name / surname / phone number / full postal address.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Silbersaiten | Order Duplicator | < 1.1.8 |
Related Weaknesses (CWE)
References
- https://security.friendsofpresta.org/modules/2023/11/07/orderduplicate.htmlThird Party Advisory
- https://security.friendsofpresta.org/modules/2023/11/07/orderduplicate.htmlThird Party Advisory
FAQ
What is CVE-2023-45380?
CVE-2023-45380 is a vulnerability with a CVSS score of 8.8 (HIGH). In the module "Order Duplicator " Clone and Delete Existing Order" (orderduplicate) in version <= 1.1.7 from Silbersaiten for PrestaShop, a guest can download personal information without restriction....
How severe is CVE-2023-45380?
CVE-2023-45380 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-45380?
Check the references section above for vendor advisories and patch information. Affected products include: Silbersaiten Order Duplicator.