Vulnerabilities > CVE-2023-45380 - Authorization Bypass Through User-Controlled Key vulnerability in Silbersaiten Order Duplicator 1.1.7

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
silbersaiten
CWE-639

Summary

In the module "Order Duplicator " Clone and Delete Existing Order" (orderduplicate) in version <= 1.1.7 from Silbersaiten for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can download personal information from ps_customer/ps_address tables such as name / surname / phone number / full postal address.

Vulnerable Configurations

Part Description Count
Application
Silbersaiten
2