CVE | CVE-2023-25170 |
CVE Title | |
Published Date | 2023-03-13T17:15Z |
Modified Date | 2023-03-13T17:26Z |
CWE Type | CWE-352 |
Description | PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). When authenticating users, PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enable same-site attackers to bypass the CSRF protection mechanism by performing an attack similar to a session-fixation. The problem is fixed in version 8.0.1. |
References | |
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites. | |
Reference URL | https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-3g43-x7qr-96ph |
Reference Description | MISC https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-3g43-x7qr-96ph |
Reference Description | |
Sources | NIST MITRE |
Note
- No CVSS data for this CVE