Vulnerabilities > CVE-2023-48926 - Missing Authorization vulnerability in Prestashop Advanced Loyalty Program

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
prestashop
CWE-862

Summary

An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily change an order status.

Vulnerable Configurations

Part Description Count
Application
Prestashop
1

Common Weakness Enumeration (CWE)