CVE-2023-30281

Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3.7.3 from Store Commander for PrestaShop, a guest can access exports from the module which can lead to leak of personnal informations from ps_customer table sush as name / surname / email
Configurations

Configuration 1 (hide)

cpe:2.3:a:storecommander:scquickaccounting:*:*:*:*:*:prestashop:*:*

History

07 Jun 2023, 01:15

Type Values Removed Values Added
Summary Insecure permissions in the ps_customer table of Prestashop scquickaccounting before v3.7.3 allows attackers to access sensitive information stored in the component. Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3.7.3 from Store Commander for PrestaShop, a guest can access exports from the module which can lead to leak of personnal informations from ps_customer table sush as name / surname / email

Information

Published : 2023-05-16 20:15

Updated : 2024-02-28 20:13


NVD link : CVE-2023-30281

Mitre link : CVE-2023-30281

CVE.ORG link : CVE-2023-30281


JSON object : View

Products Affected

storecommander

  • scquickaccounting