Vulnerabilities > CVE-2023-43984 - Unspecified vulnerability in Advanced Export products Orders Cron CSV Excel Project Advanced Export products Orders Cron CSV Excel

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE

Summary

Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download user information from the ps_customer table.

Vulnerable Configurations

Part Description Count
Application
Advanced_Export_Products_Orders_Cron_Csv_Excel_Project
20