CVE-2023-47109

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-47109
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-47109.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-47109
Aliases
Published
2023-11-08T22:15:10Z
Modified
2024-05-15T01:18:54.642461Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
[none]
Details

PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy. When adding a block in blockreassurance module, a BO user can modify the http request and give the path of any file in the project instead of an image. When deleting the block from the BO, the file will be deleted. It is possible to make the website completely unavailable by removing index.php for example. This issue has been patched in version 5.1.4.

References

Affected packages

Git / github.com/prestashop/blockreassurance

Affected ranges

Type
GIT
Repo
https://github.com/prestashop/blockreassurance
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

v1.*

v1.0.1
v1.0.5
v1.0.6

v2.*

v2.0.0
v2.0.1
v2.0.2
v2.0.3

v3.*

v3.0.0
v3.0.1

v4.*

v4.1.0
v4.1.1

v5.*

v5.0.0