CVE-2024-25840
27.02.2024, 17:15
In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack.Enginsight
Vendor | Product | Version |
---|---|---|
prestaworld | account_manager | 𝑥 < 9.0.0 |
𝑥
= Vulnerable software versions
References