CVE-2024-34717

CVSS V2 None CVSS V3 None
Description
PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by supplying a random secure_key parameter in the url. This issue is patched in version 8.1.6. No known workarounds are available.
Overview
  • CVE ID
  • CVE-2024-34717
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-05-14T15:47:27.265Z
  • Last Modified Date
  • 2024-06-04T17:41:41.822Z
History
Created Old Value New Value Data Type Notes
2024-06-26 14:19:51 Added to TrackCVE