PrestaShop allows users to uninstall modules from backoffice, even with low rights
Moderate severity
GitHub Reviewed
Published
Sep 28, 2023
in
PrestaShop/PrestaShop
•
Updated Nov 7, 2023
Description
Published to the GitHub Advisory Database
Sep 28, 2023
Reviewed
Sep 28, 2023
Published by the National Vulnerability Database
Sep 28, 2023
Last updated
Nov 7, 2023
Impact
Any module can be disabled or uninstalled from back office, even with low user right.
Patches
8.1.2
Workarounds
none
References
References