CVE-2023-30196

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published May 30, 2023
Updated: Jan 13, 2025
CWE ID 346
CWE ID 22

Summary

CVE-2023-30196: A new vulnerability affecting Prestashop salesbooster versions below 1.10.5 has been identified. The issue lies in the download.php file located in the modules/salesbooster/downloads directory. The flaw permits incorrect access control, potentially allowing unauthorized users to download files they should not have access to, posing a significant risk to data confidentiality. It is crucial for users to update to the latest version of salesbooster to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share