PrestaShop allows employee without any access rights to list all installed modules
Moderate severity
GitHub Reviewed
Published
Sep 28, 2023
in
PrestaShop/PrestaShop
•
Updated Nov 11, 2023
Description
Published to the GitHub Advisory Database
Sep 28, 2023
Reviewed
Sep 28, 2023
Published by the National Vulnerability Database
Sep 28, 2023
Last updated
Nov 11, 2023
Impact
In BO, an employee can list all modules without any access rights: method
ajaxProcessGetPossibleHookingListForModule
doesn't check access rightsPatches
Fixed on 8.1.2
Workarounds
References
References