PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit `ce1f6708` addresses this issue and is included in version 8.1.2. Users are advised to upgrade. There are no known workarounds for this issue.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-2445 PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit `ce1f6708` addresses this issue and is included in version 8.1.2. Users are advised to upgrade. There are no known workarounds for this issue.
Github GHSA Github GHSA GHSA-6jmf-2pfc-q9m7 PrestaShop allows users to uninstall modules from backoffice, even with low rights
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 20 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-09-20T19:32:29.398Z

Reserved: 2023-09-20T15:35:38.148Z

Link: CVE-2023-43663

cve-icon Vulnrichment

Updated: 2024-08-02T19:44:43.764Z

cve-icon NVD

Status : Modified

Published: 2023-09-28T19:15:10.633

Modified: 2024-11-21T08:24:34.407

Link: CVE-2023-43663

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.