In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while SHOP is in maintenance mode. Due to a lack of permissions control, a guest can access the txt file which collect email when maintenance is enable which can lead to leak of personal information.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T03:37:05.324Z

Reserved: 2024-05-30T00:00:00

Link: CVE-2024-36682

cve-icon Vulnrichment

Updated: 2024-08-02T03:37:05.324Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-24T22:15:10.377

Modified: 2024-11-21T09:22:32.397

Link: CVE-2024-36682

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.