Improper Authorization Affecting prestashop/blockreassurance package, versions <5.1.4


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.1% (43rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-PRESTASHOPBLOCKREASSURANCE-6052821
  • published9 Nov 2023
  • disclosed8 Nov 2023
  • creditUnknown

Introduced: 8 Nov 2023

CVE-2023-47109  (opens in a new tab)
CWE-285  (opens in a new tab)

How to fix?

Upgrade prestashop/blockreassurance to version 5.1.4 or higher.

Overview

Affected versions of this package are vulnerable to Improper Authorization such that when adding a block in the blockreassurance module, a back-office user can manipulate the HTTP request and specify the path of any file in the project instead of an image. By deleting the block from the back-office, the specified file will be removed. This can lead to the website becoming completely unavailable if critical files such as index.php are removed.

CVSS Scores

version 3.1