CVE-2023-45382
17.11.2023, 02:15
In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| common-services | sonice_retour | 𝑥 ≤ 2.1.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| sonice_retour | common_services_for_prestashop | 𝑥 ≤ 2.1.0 | ADP |