In the module "Theme settings"... CVE-2024-36682

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while SHOP is in maintenance mode. Due to a lack of permissions control, a guest can access the txt file which collect email when maintenance is enable which can lead to leak of personal information.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息