Vulnerabilities > CVE-2023-30195 - Missing Authorization vulnerability in Lineagrafica Lgdetailedorder 1.1.20

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
lineagrafica
CWE-862

Summary

In the module "Detailed Order" (lgdetailedorder) in version up to 1.1.20 from Linea Grafica for PrestaShop, a guest can download personal informations without restriction formatted in json.

Vulnerable Configurations

Part Description Count
Application
Lineagrafica
2

Common Weakness Enumeration (CWE)