mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-06-07 05:28:59 +00:00
20 lines
836 B
JSON
20 lines
836 B
JSON
![]() |
{
|
||
|
"id": "CVE-2023-46354",
|
||
|
"sourceIdentifier": "cve@mitre.org",
|
||
|
"published": "2023-12-06T23:15:07.380",
|
||
|
"lastModified": "2023-12-06T23:15:07.380",
|
||
|
"vulnStatus": "Received",
|
||
|
"descriptions": [
|
||
|
{
|
||
|
"lang": "en",
|
||
|
"value": "In the module \"Orders (CSV, Excel) Export PRO\" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from ps_customer/ps_address tables such as name / surname / email / phone number / full postal address."
|
||
|
}
|
||
|
],
|
||
|
"metrics": {},
|
||
|
"references": [
|
||
|
{
|
||
|
"url": "https://security.friendsofpresta.org/modules/2023/11/28/ordersexport.html",
|
||
|
"source": "cve@mitre.org"
|
||
|
}
|
||
|
]
|
||
|
}
|