GHSA-xfm3-hjcc-gv78

Suggest an improvement
Source
https://github.com/advisories/GHSA-xfm3-hjcc-gv78
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-xfm3-hjcc-gv78/GHSA-xfm3-hjcc-gv78.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xfm3-hjcc-gv78
Aliases
Published
2023-11-09T16:02:38Z
Modified
2024-02-16T08:18:56.281601Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Any value can be changed in the configuration table by an employee having access to block reassurance module
Details

Impact

An ajax function in module blockreassurance allows modifying any value in the configuration table

Patches

v5.1.4

Workarounds

no workaround available

References

Database specific
{
    "nvd_published_at": "2023-11-09T16:15:34Z",
    "cwe_ids": [
        "CWE-284"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-11-09T16:02:38Z"
}
References

Affected packages

Packagist / prestashop/blockreassurance

Package

Name
prestashop/blockreassurance
Purl
pkg:composer/prestashop/blockreassurance

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.1.4

Affected versions

v1.*

v1.0.1
v1.0.5
v1.0.6

v2.*

v2.0.0
v2.0.1
v2.0.2
v2.0.3

v3.*

v3.0.0
v3.0.1

v4.*

v4.1.0
v4.1.1

v5.*

v5.0.0
v5.1.0
v5.1.1
v5.1.2
v5.1.3

Database specific

{
    "last_known_affected_version_range": "<= 5.1.3"
}