Vulnerability Description
PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy. When adding a block in blockreassurance module, a BO user can modify the http request and give the path of any file in the project instead of an image. When deleting the block from the BO, the file will be deleted. It is possible to make the website completely unavailable by removing index.php for example. This issue has been patched in version 5.1.4.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Prestashop | Customer Reassurance Block | < 5.1.4 |
Related Weaknesses (CWE)
References
- https://github.com/PrestaShop/blockreassurance/commit/2d0e97bebf795690caffe33c1aPatch
- https://github.com/PrestaShop/blockreassurance/commit/eec00da564db4c1804b0a0d1e3Patch
- https://github.com/PrestaShop/blockreassurance/releases/tag/v5.1.4Release Notes
- https://github.com/PrestaShop/blockreassurance/security/advisories/GHSA-83j2-qhxVendor Advisory
- https://github.com/PrestaShop/blockreassurance/commit/2d0e97bebf795690caffe33c1aPatch
- https://github.com/PrestaShop/blockreassurance/commit/eec00da564db4c1804b0a0d1e3Patch
- https://github.com/PrestaShop/blockreassurance/releases/tag/v5.1.4Release Notes
- https://github.com/PrestaShop/blockreassurance/security/advisories/GHSA-83j2-qhxVendor Advisory
FAQ
What is CVE-2023-47109?
CVE-2023-47109 is a vulnerability with a CVSS score of 5.5 (MEDIUM). PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy. When adding a block in blockreassurance module, a BO us...
How severe is CVE-2023-47109?
CVE-2023-47109 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-47109?
Check the references section above for vendor advisories and patch information. Affected products include: Prestashop Customer Reassurance Block.