Description
In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while SHOP is in maintenance mode. Due to a lack of permissions control, a guest can access the txt file which collect email when maintenance is enable which can lead to leak of personal information.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T03:37:05.324Z
Reserved: 2024-05-30T00:00:00.000Z
Link: CVE-2024-36682
Updated: 2024-08-02T03:37:05.324Z
Status : Deferred
Published: 2024-06-24T22:15:10.377
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-36682
No data.
OpenCVE Enrichment
No data.
Weaknesses