CVE-2023-30197

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published May 31, 2023
Updated: Jan 9, 2025
CWE ID 22

Summary

CVE-2023-30197 is a newly identified vulnerability affecting the "My inventory" module (myinventory) in Webbax for PrestaShop, version 1.6.6 and below. This issue involves incorrect access control, enabling unauthorized guests to execute a path traversal attack. By exploiting this weakness, attackers can gain access to personal information belonging to other users, posing a significant privacy risk. The vulnerability can be addressed by upgrading to the latest version of the module or implementing appropriate access control measures.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share