Executive brief
PrestaShop allows employee without any access rights to list all installed modules
Affected products
- Packagist prestashop/prestashop
Junglewise Threat Intelligence
CVE-2023-43664 · Severity: low · CVSS 3.1 · Published 2023-09-28
Technologies: prestashop/prestashop (Packagist). Vendors: Packagist.
PrestaShop allows employee without any access rights to list all installed modules