CVE-2023-30196
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published May 30, 2023
Updated: Jan 13, 2025
CWE ID 346
CWE ID 22
Summary
CVE-2023-30196: A new vulnerability affecting Prestashop salesbooster versions below 1.10.5 has been identified. The issue lies in the download.php file located in the modules/salesbooster/downloads directory. The flaw permits incorrect access control, potentially allowing unauthorized users to download files they should not have access to, posing a significant risk to data confidentiality. It is crucial for users to update to the latest version of salesbooster to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.