CVSS 3.1 Score 7.5 of 10 (high)


Published Nov 17, 2023
Updated: Nov 25, 2023


CVE-2023-45382 is a vulnerability found in the "SoNice Retour" module (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop. This vulnerability allows an unauthorized guest to perform a path traversal attack, enabling them to download personal information without any restrictions. The lack of permissions control and control in the path name construction allows the guest to view all files on the information system. The affected products include t0RzSJ and t0RzSK. To remediate this vulnerability, it is recommended to update the "SoNice Retour" module to a version beyond 2.1.0 or apply any available patches provided by Common-Services for PrestaShop. This vulnerability poses a high danger to organizations as it allows unauthorized access to sensitive personal information, potentially leading to data breaches and privacy violations.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-45382 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options