Record summary

CVE-2023-39677 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 25, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryHIGHPrestaShop MyPrestaModules - PhpInfo DisclosureCVSS 7.5

PrestaShop modules by MyPrestaModules expose PHPInfo

Impact

An attacker can exploit this vulnerability to obtain sensitive information about the server configuration, potentially leading to further attacks.

Remediation

Apply the latest security patches and updates from the vendor to address this vulnerability.

Authorsmeme-lord
Template tagscve2023cveprestashopphpinfodisclosuresimpleimportproduct_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:simpleimportproduct_project:simpleimportproduct:6.2.9:*:*:*:*:prestashop:*:*
Shodan: http.component:"PrestaShop"
Shodan: http.component:"prestashop"

Source: ProjectDiscovery

References

4